To rate attack feasibility, one of three methods should be used, attack-potential-based, CVSS-based or attack-vector-based, picked according to the lifecycle phase and the information at hand.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.