Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Authority · Co-dominant path
Firmware trust root
Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.
Proximity or local access
The monitor connects to a hard-coded routable NFS host, so exploitation depends on controlling or intercepting that network position.
EvidenceCISA ICSMA-25-030-01
Cross-domain authority chain
The default NFS fetch bridges a network host into persistent code execution and then into clinical monitoring behavior.
EvidenceNo direct citation — inspect the declared inference or assumption.
Firmware or trust-root authority
Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.
EvidenceNo direct citation — inspect the declared inference or assumption.
Firmware trust root
Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
The absence of a signed update path means recovery must replace or verify firmware across affected devices rather than apply a simple configuration change.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The monitor connects to a hard-coded routable NFS host, so exploitation depends on controlling or intercepting that network position.
- Execution complexity
EC 3 - Reproducible exploit workflow
Serving a compatible replacement binary is reproducible, but requires understanding the NFS layout and expected executable format.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Code loaded as monitor firmware can suppress alarms or falsify patient state, creating a credible wrong-care pathway without claiming observed injury.
- Data / perception
DP 3 - Sensitive device or personal data
Firmware-level code can read sensitive patient and operational state handled by the monitor.
- Authority
AT 4 - Firmware or trust-root authority
Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The default NFS fetch bridges a network host into persistent code execution and then into clinical monitoring behavior.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same hard-coded host and unsigned load design is shared across affected CMS8000 units and rebrands.
- Execution scale
SX 3 - Deployment-wide with setup
An attacker with the required network position can repeat the replacement across reachable monitors, but setup is deployment-dependent.
- Recovery burden
OR 4 - Fleet action or replacement
The absence of a signed update path means recovery must replace or verify firmware across affected devices rather than apply a simple configuration change.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
CISA ICSMA-25-030-01 supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unsigned binaries copied into the executable directory run as trusted monitor code beneath normal application controls.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:2/EC:3/EX:2/PH:4/DP:3/AT:4/CH:4/SR:4/SX:3/OR:4/EV:3/LS:ACTIVERead the scoring method →Safety · Co-dominant path
Device-control safety
Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.
Proximity or local access
Control begins when a monitor reaches the hard-coded NFS address and accepts content from an attacker-controlled or intercepted endpoint.
EvidenceCISA ICSMA-25-030-01
Cross-domain authority chain
Network content becomes executable monitor behavior and then influences a clinical perception-to-care boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Restoring confidence requires verified firmware across the installed base because ordinary updates do not establish signed provenance.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Control begins when a monitor reaches the hard-coded NFS address and accepts content from an attacker-controlled or intercepted endpoint.
- Execution complexity
EC 3 - Reproducible exploit workflow
The attacker must prepare monitor-compatible code and gain the required network position, a standard but deliberate exploitation workflow.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.
- Data / perception
DP 4 - Safety-driving perception or intimate data
The manipulated patient-monitoring state is perception data that can directly shape clinical decisions.
- Authority
AT 3 - Administrative or command authority
Executed replacement code can control monitor software and alarm behavior, though this path distinguishes device command authority from the signing root itself.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Network content becomes executable monitor behavior and then influences a clinical perception-to-care boundary.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same insecure loading behavior is present across the affected product family, making the technique portable.
- Execution scale
SX 3 - Deployment-wide with setup
Multiple reachable monitors can be targeted after deployment-specific network positioning, rather than through a universal internet endpoint.
- Recovery burden
OR 4 - Fleet action or replacement
Restoring confidence requires verified firmware across the installed base because ordinary updates do not establish signed provenance.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
CISA ICSMA-25-030-01 reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Malicious monitor code can falsify displayed vitals or suppress alarms that clinicians use, supporting a serious safety consequence without proving field harm.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:3/EX:2/PH:4/DP:4/AT:3/CH:4/SR:4/SX:3/OR:4/EV:2/LS:ACTIVERead the scoring method →Privacy · Co-dominant path
Data privacy
The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.
Network-reachable without prior access
The monitor sends plaintext patient information to a hard-coded routable address by default, exposing the flow wherever that route can be observed or controlled.
EvidenceCISA ICSMA-25-030-01
Reusable multi-stage bridge
A default device configuration moves clinical data across the monitor and network boundary to an external host.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires changing the destination and validating network and device configuration across deployed monitors.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The monitor sends plaintext patient information to a hard-coded routable address by default, exposing the flow wherever that route can be observed or controlled.
- Execution complexity
EC 4 - Straightforward operation
Receiving or observing the default plaintext beacon is straightforward once the network path is available.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 0 - No direct physical effect
The same channel carries clinical state used in care, but this privacy path does not assert that disclosure alone caused patient harm.
- Data / perception
DP 3 - Sensitive device or personal data
The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.
- Authority
AT 2 - Bounded function authority
Receiving the beacon grants bounded access to exported data, not administrative control of the monitor or its firmware trust root.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
A default device configuration moves clinical data across the monitor and network boundary to an external host.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The destination and beacon behavior are shared across affected monitors, so the collection method can be reused.
- Execution scale
SX 4 - Remote fleet-scale execution
Plaintext egress can be collected across reachable units without interacting with each patient interface separately.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires changing the destination and validating network and device configuration across deployed monitors.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
CISA ICSMA-25-030-01 supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. The beacon contains patient health information rather than low-sensitivity diagnostics or generic device telemetry.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:0/DP:3/AT:2/CH:3/SR:4/SX:4/OR:3/EV:3/LS:ACTIVERead the scoring method →Triage implication
Verify the authority transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisory
- otherClaroty Team82
Claroty Team82
- advisory
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NCVE recordsCVE-2025-0626CVE-2025-0683
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
TL;DR
The Paths model rates all three paths CRITICAL because the device blindly loads unsigned firmware from a hard-coded routable IP. That trust-root failure forks into three distinct terminal harms: firmware control, safety/perception, and PHI egress. The published 7.7 / 8.2 baseline is retained for source review; the Paths drivers are multi-path consequence and hard recovery.
What it is
The CMS8000 mounts NFS from a hard-coded, routable IP and copies binaries to /opt/bin with no signature check, forcing the network interface up. It also beacons plaintext patient data (PHI) to that hard-coded address by default. Claroty Team82 reproduced the unsigned-code load and PHI egress, and — importantly — concluded this is insecure design, not a covert “backdoor.” (CISA ICSMA-25-030-01; Claroty Team82.)
Published baseline — scope note
Two bends, neither in the digit. (1) Label/narrative: CISA classed it CWE-912 “hidden functionality” and advised ripping devices off networks; the careful technical read (Team82) is “documented, insecure CMS default.” Same bytes, very different response — supplied by country-of-origin, not code (requirement #7). (2) Collapse: a single 7.7/8.2 cannot represent that one trust-root failure yields three terminal consequences at once, nor that there is no signed-update path to recover (the vendor shipped non-fixes).
Consequence driver
The Paths model highlights #2 (chain/multi-path) — one trust-root failure forks into three terminal harms a single number collapses; #8 (recoverability) — there is no signed-update path, so this is hard to fix in place; and #7 (narrative-invariance) — the “backdoor” framing moved the response, not the bytes.
Sources
- CISA: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-030-01
- Claroty Team82: https://claroty.com/team82/research/are-contec-cms8000-patient-monitors-infected-with-a-chinese-backdoor-the-reality-is-more-complicated
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2025-0626 · https://nvd.nist.gov/vuln/detail/CVE-2024-12248
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0003 (“Contec CMS8000 — unsigned-firmware load / hard-coded beacon”), paths.cfse.ai/CPATH-2026-0003 (published 2026-06-03).