← Registry

CPATH-2026-0004 · MEDICAL IOT

Baxter Life2000 internal JTAG flash R/W

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence DEVICE_CONTROL_SAFETY Physical/safety · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE
CPATH IDCPATH-2026-0004
CVE(s)CVE-2024-48970
Device / classBaxter Life2000 internal JTAG flash R/W (MEDICAL IOT)
VendorBaxter
Dominant consequenceDEVICE_CONTROL_SAFETY (Physical/safety)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline
v3.1 9.3 CRITICAL CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · Baxter/Product Security via NVD
Baseline relationship◀▶ comparable
Consequence dimension(s)#1 #2 #7 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

Physical/safety

DEVICE_CONTROL_SAFETY

CRITICAL
Reachability RE:1
Complexity EC:3
Consequence DEVICE_CONTROL_SAFETY
Scale SR:4 / SX:1
Verdict CRITICAL
Reachability 1
Complexity 3
Exposure 1
Physical / safety 4
Data / perception 3
Authority 3
Chainability 3
Reuse scale 4
Execution scale 1
Recovery 4
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

authority

FIRMWARE_TRUST_ROOT

CRITICAL
Reachability RE:1
Complexity EC:4
Consequence FIRMWARE_TRUST_ROOT
Scale SR:4 / SX:1
Verdict CRITICAL
Reachability 1
Complexity 4
Exposure 1
Physical / safety 4
Data / perception 3
Authority 4
Chainability 4
Reuse scale 4
Execution scale 1
Recovery 4
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

Assessment

CFSE Consequence Paths assesses Baxter Life2000 internal JTAG flash R/W at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Baxter Life2000 internal JTAG flash R/W. Reported attack vector: Local (should be Physical - internal header).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

FIRMWARE_TRUST_ROOTCRITICAL

CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

JTAG flash R/W on an MCU with no memory protection means the attacker can read and rewrite firmware, owning the device’s code-execution trust root and persisting through reflash/reboot. RE:1 because it requires opening the device and clipping onto an internal header (board access, per-device physical/invasive, not internet/proximity). EC:4 once attached JTAG read/write is single-tool commodity. AT:4 firmware R/W = control over the device’s root of trust/code execution. PH:3 firmware compromise can alter ventilator therapy behavior (safety-margin/therapy-control influence). DP:3 firmware/CSP exposure (proprietary/sensitive secrets). CH:4 a reusable cross-boundary bridge (physical->firmware->control) and the knowledge/secret extraction reuses across all units of the model. SR:4 firmware and any embedded keys/CSPs are portable across the model line. SX:1 each device must be physically opened. OR:4 persistent, hard to detect, requires field service to recover; but per-device service not a fleet/OTA-root rotation, so recovery_needs_fleet_action=false. EV:2 report-backed (CVE-2024-48970, no public reproduction). LS PATCH_AVAILABLE.

Published baseline

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0004 (“Baxter Life2000 internal JTAG flash R/W”), paths.cfse.ai/CPATH-2026-0004 (published 2026-06-03).