CPATH-2026-0004 · Medical IoT

Baxter Life2000 internal JTAG flash R/W

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsDevice-control safety + Firmware trust root

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.

CRITICAL
  1. accessSource-backed

    Per-device physical access

    Internal JTAG header requires opening the device, board-level access, per-device.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Chains physical access into safety actuation across boundaries.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Persistent and hard to detect, needs field service.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 1
Per-device physical access

Internal JTAG header requires opening the device, board-level access, per-device.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Changing therapy behavior requires more than dumping flash: the attacker must prepare and install a deliberate firmware or control modification.

Source-backedNVD
ExposureEX 1
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Modified device code can expose ventilator settings and other sensitive operational state.

Model inference
AuthorityAT 3
Administrative or command authority

Flash modification provides device-command and firmware authority, but it does not expose a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Chains physical access into safety actuation across boundaries.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The technique and any extracted secrets are reusable across the model.

Operational assumption
Execution scaleSX 1
One device at a time

Strictly per-device physical access.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Persistent and hard to detect, needs field service.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Direct flash modification can alter ventilator therapy or disable life-support behavior, creating a credible risk of serious patient injury.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Authority · Co-dominant path

Firmware trust root

Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.

CRITICAL
  1. accessSource-backed

    Per-device physical access

    An attacker must open each ventilator and attach to its internal JTAG header; the interface is neither remotely nor wirelessly reachable.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Physical JTAG access crosses into firmware authority and then device control; extracted knowledge or secrets can be reused across units.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Firmware or trust-root authority

    Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Firmware trust root

    Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Persistent, hard to detect, requires field service to recover.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 1
Per-device physical access

An attacker must open each ventilator and attach to its internal JTAG header; the interface is neither remotely nor wirelessly reachable.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Once a JTAG connection is established, one hardware-debugging tool can read or write the flash.

Source-backedNVD
ExposureEX 1
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Firmware compromise can alter therapy-control behavior and reduce the ventilator’s safety margin.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Flash contents can expose proprietary firmware and embedded cryptographic secrets.

Model inference
AuthorityAT 4
Firmware or trust-root authority

Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Physical JTAG access crosses into firmware authority and then device control; extracted knowledge or secrets can be reused across units.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Extracted firmware and embedded keys can be reused across devices in the same product line.

Operational assumption
Execution scaleSX 1
One device at a time

Each device must be physically opened.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Persistent, hard to detect, requires field service to recover.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Read and write access to internal flash lets an attacker replace trusted device code and take control beneath the application layer.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:3/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipDifferent consequence axis
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.3 CRITICALBaxter/Product Security via NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Baxter Life2000 internal JTAG flash R/W at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Baxter Life2000 internal JTAG flash R/W. Reported attack vector: Local (should be Physical - internal header).

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:1/EC:3/EX:1/PH:4/DP:3/AT:3/CH:3/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

  • Writing flash lets the attacker modify control firmware on a life-support ventilator, enabling dangerous therapy alteration. RE:1 internal JTAG header requires opening the device, board-level access, per-device. EC:3 crafting a malicious firmware/control modification that actually alters therapy is a standard-but-deliberate researcher workflow beyond a raw flash dump. PH:4 credible serious injury/death from altered ventilator therapy / life-support failure. AT:3 control authority modifying firmware/command behavior of the device. DP:3 sensitive operational/firmware state. CH:3 chains physical access into safety actuation across boundaries. SR:4 the technique and any extracted secrets are reusable across the model. SX:1 strictly per-device physical access. OR:4 persistent and hard to detect, needs field service; per-device so recovery_needs_fleet_action=false.
  • perception_feeds_action — false (this is direct actuation control, not a perception channel feeding action). EV:2 report-backed. LS PATCH_AVAILABLE.

FIRMWARE_TRUST_ROOTCRITICAL

CPATH:1.0-candidate/TT:FIRMWARE_TRUST_ROOT/RE:1/EC:4/EX:1/PH:4/DP:3/AT:4/CH:4/SR:4/SX:1/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

JTAG flash R/W on an MCU with no memory protection means the attacker can read and rewrite firmware, owning the device’s code-execution trust root and persisting through reflash/reboot. RE:1 because it requires opening the device and clipping onto an internal header (board access, per-device physical/invasive, not internet/proximity). EC:4 once attached JTAG read/write is single-tool commodity. AT:4 firmware R/W = control over the device’s root of trust/code execution. PH:3 firmware compromise can alter ventilator therapy behavior (safety-margin/therapy-control influence). DP:3 firmware/CSP exposure (proprietary/sensitive secrets). CH:4 a reusable cross-boundary bridge (physical->firmware->control) and the knowledge/secret extraction reuses across all units of the model. SR:4 firmware and any embedded keys/CSPs are portable across the model line. SX:1 each device must be physically opened. OR:4 persistent, hard to detect, requires field service to recover; but per-device service not a fleet/OTA-root rotation, so recovery_needs_fleet_action=false. EV:2 report-backed (CVE-2024-48970, no public reproduction). LS PATCH_AVAILABLE.

Published baseline

  • v3.1 9.3 CRITICAL — CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — Baxter/Product Security via NVD

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0004 (“Baxter Life2000 internal JTAG flash R/W”), paths.cfse.ai/CPATH-2026-0004 (published 2026-06-03).