Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.
Per-device physical access
Internal JTAG header requires opening the device, board-level access, per-device.
EvidenceNVD
Reusable multi-stage bridge
Chains physical access into safety actuation across boundaries.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Persistent and hard to detect, needs field service.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 1 - Per-device physical access
Internal JTAG header requires opening the device, board-level access, per-device.
- Execution complexity
EC 3 - Reproducible exploit workflow
Changing therapy behavior requires more than dumping flash: the attacker must prepare and install a deliberate firmware or control modification.
- Exposure
EX 1 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.
- Data / perception
DP 3 - Sensitive device or personal data
Modified device code can expose ventilator settings and other sensitive operational state.
- Authority
AT 3 - Administrative or command authority
Flash modification provides device-command and firmware authority, but it does not expose a vendor signing key.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Chains physical access into safety actuation across boundaries.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The technique and any extracted secrets are reusable across the model.
- Execution scale
SX 1 - One device at a time
Strictly per-device physical access.
- Recovery burden
OR 4 - Fleet action or replacement
Persistent and hard to detect, needs field service.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Authority · Co-dominant path
Firmware trust root
Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.
Per-device physical access
An attacker must open each ventilator and attach to its internal JTAG header; the interface is neither remotely nor wirelessly reachable.
EvidenceNVD
Cross-domain authority chain
Physical JTAG access crosses into firmware authority and then device control; extracted knowledge or secrets can be reused across units.
EvidenceNo direct citation — inspect the declared inference or assumption.
Firmware or trust-root authority
Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.
EvidenceNo direct citation — inspect the declared inference or assumption.
Firmware trust root
Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Persistent, hard to detect, requires field service to recover.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 1 - Per-device physical access
An attacker must open each ventilator and attach to its internal JTAG header; the interface is neither remotely nor wirelessly reachable.
- Execution complexity
EC 4 - Straightforward operation
Once a JTAG connection is established, one hardware-debugging tool can read or write the flash.
- Exposure
EX 1 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Firmware compromise can alter therapy-control behavior and reduce the ventilator’s safety margin.
- Data / perception
DP 3 - Sensitive device or personal data
Flash contents can expose proprietary firmware and embedded cryptographic secrets.
- Authority
AT 4 - Firmware or trust-root authority
Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Physical JTAG access crosses into firmware authority and then device control; extracted knowledge or secrets can be reused across units.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Extracted firmware and embedded keys can be reused across devices in the same product line.
- Execution scale
SX 1 - One device at a time
Each device must be physically opened.
- Recovery burden
OR 4 - Fleet action or replacement
Persistent, hard to detect, requires field service to recover.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:3/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVE recordsCVE-2024-48970
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Baxter Life2000 internal JTAG flash R/W at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Baxter Life2000 internal JTAG flash R/W. Reported attack vector: Local (should be Physical - internal header).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.
- Writing flash lets the attacker modify control firmware on a life-support ventilator, enabling dangerous therapy alteration. RE:1 internal JTAG header requires opening the device, board-level access, per-device. EC:3 crafting a malicious firmware/control modification that actually alters therapy is a standard-but-deliberate researcher workflow beyond a raw flash dump. PH:4 credible serious injury/death from altered ventilator therapy / life-support failure. AT:3 control authority modifying firmware/command behavior of the device. DP:3 sensitive operational/firmware state. CH:3 chains physical access into safety actuation across boundaries. SR:4 the technique and any extracted secrets are reusable across the model. SX:1 strictly per-device physical access. OR:4 persistent and hard to detect, needs field service; per-device so recovery_needs_fleet_action=false.
- perception_feeds_action — false (this is direct actuation control, not a perception channel feeding action). EV:2 report-backed. LS PATCH_AVAILABLE.
FIRMWARE_TRUST_ROOT → CRITICAL
CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.
JTAG flash R/W on an MCU with no memory protection means the attacker can read and rewrite firmware, owning the device’s code-execution trust root and persisting through reflash/reboot. RE:1 because it requires opening the device and clipping onto an internal header (board access, per-device physical/invasive, not internet/proximity). EC:4 once attached JTAG read/write is single-tool commodity. AT:4 firmware R/W = control over the device’s root of trust/code execution. PH:3 firmware compromise can alter ventilator therapy behavior (safety-margin/therapy-control influence). DP:3 firmware/CSP exposure (proprietary/sensitive secrets). CH:4 a reusable cross-boundary bridge (physical->firmware->control) and the knowledge/secret extraction reuses across all units of the model. SR:4 firmware and any embedded keys/CSPs are portable across the model line. SX:1 each device must be physically opened. OR:4 persistent, hard to detect, requires field service to recover; but per-device service not a fleet/OTA-root rotation, so recovery_needs_fleet_action=false. EV:2 report-backed (CVE-2024-48970, no public reproduction). LS PATCH_AVAILABLE.
Published baseline
- v3.1 9.3 CRITICAL —
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H— Baxter/Product Security via NVD
The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0004 (“Baxter Life2000 internal JTAG flash R/W”), paths.cfse.ai/CPATH-2026-0004 (published 2026-06-03).