CPATH-2026-0005 · Medical IoT

Baxter Life2000 hard-coded clinician credentials

A dominant account authority path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathAccount authority

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Dominant path

Account authority

The credential opens a clinician account that can change therapy settings, but it does not grant operating-system root or firmware-signing authority.

CRITICAL
  1. accessSource-backed

    Reusable artifact or reachable service

    The hard-coded clinician and serial-number credentials can be recovered from an attacker-owned device or firmware copy without touching a victim device.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The recovered shared secret bridges from device-extraction to a reusable authority across the fleet.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Bounded function authority

    The credential opens a clinician account that can change therapy settings, but it does not grant operating-system root or firmware-signing authority.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The credential opens a clinician account that can change therapy settings, but it does not grant operating-system root or firmware-signing authority.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    A hard-coded secret cannot be rotated without firmware update across the fleet; fleet-wide recovery is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 3
Reusable artifact or reachable service

The hard-coded clinician and serial-number credentials can be recovered from an attacker-owned device or firmware copy without touching a victim device.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Extraction is straightforward once firmware and device available.

Source-backedNVD
ExposureEX 3
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

The shared clinician credential can authorize changes to ventilator therapy settings, so compromise can reach a severe therapy consequence even though this path ends at account authority.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The exposed clinician credential is a reusable security secret rather than ordinary device telemetry.

Model inference
AuthorityAT 2
Bounded function authority

The credential opens a clinician account that can change therapy settings, but it does not grant operating-system root or firmware-signing authority.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The recovered shared secret bridges from device-extraction to a reusable authority across the fleet.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The credential is shared and hard-coded across the entire fleet (portable secret).

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

Reusable deployment-wide but each device still needs local and serial access to apply.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

A hard-coded secret cannot be rotated without firmware update across the fleet; fleet-wide recovery is required.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. The credential opens a clinician account that can change therapy settings, but it does not grant operating-system root or firmware-signing authority.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Safety · Supporting path

Device-control safety

Clinician-level setting changes can alter ventilator therapy and reduce patient safety margins, even without operating-system or firmware control.

HIGH
  1. accessSource-backed

    Proximity or local access

    Using the recovered clinician credential against a ventilator requires local or serial access to that target device.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Crosses credential to device to physical and safety domains.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Credible safety consequence

    Clinician-level setting changes can alter ventilator therapy and reduce patient safety margins, even without operating-system or firmware control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Clinician-level setting changes can alter ventilator therapy and reduce patient safety margins, even without operating-system or firmware control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Unfixable secret without firmware update; fleet-wide recovery is required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

Using the recovered clinician credential against a ventilator requires local or serial access to that target device.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

After the shared clinician credential is accepted, changing therapy settings uses the ventilator's ordinary clinical workflow.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 3
Credible safety consequence

Clinician-level setting changes can alter ventilator therapy and reduce patient safety margins, even without operating-system or firmware control.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The clinician interface exposes therapy settings and sensitive device state, but not a broader patient-record store.

Model inference
AuthorityAT 3
Administrative or command authority

The clinician account can change therapy settings and device operation, but it does not provide firmware-signing or operating-system root authority.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Crosses credential to device to physical and safety domains.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The hard-coded credential can be reused across affected ventilators that share the same implementation.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each use still requires access to an individual ventilator; the weakness does not provide a fleet execution channel.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Unfixable secret without firmware update; fleet-wide recovery is required.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. Clinician-level setting changes can alter ventilator therapy and reduce patient safety margins, even without operating-system or firmware control.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipDifferent consequence axis
Baseline confidencehigh
Scored2026-06-03
v3.1 · 9.3 CRITICALBaxter/Product Security via NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Baxter Life2000 hard-coded clinician credentials at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is privileged account or control authority.

Vulnerability

Baxter Life2000 hard-coded clinician credentials. Reported attack vector: Local.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.

  • Using the recovered clinician credential to log into a Life2000 ventilator and change therapy settings. RE:2 requires local/serial proximity to the target device to apply the privileges. EC:4 once authenticated, changing settings is the device’s normal trivial workflow. AT:3 clinician-level control of therapy settings is service/command authority modifying device operation (not root-of-trust, so not 4). PH:3 altering ventilator therapy settings reduces safety margins / can cause unsafe therapy on a life-support device; credible harm but mediated by needing local access and clinical oversight, so 3 rather than 4. DP:3 sensitive operational/therapy state. CH:4 / boundary_crossing: crosses credential->device->physical/safety domains. SR:4 same shared hard-coded credential. SX:2 per-device, requires local/serial proximity. OR:4 unfixable secret without firmware update -> recovery_needs_fleet_action.
  • perception_feeds_action — false: this is direct actuation control, not manipulated perception driving action. EV:2 report-backed, PATCH_AVAILABLE.

ACCOUNT_AUTHORITYCRITICAL

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=3 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.

Hard-coded Clinician / Serial-Number Clinician passwords extracted from device firmware (RE:3 attacker uses own device/firmware copy, no victim hardware needed; AV:L but extractable from any unit). Extraction is straightforward once firmware/device available (EC:4). AT:2 because it grants a bounded clinician-level account, not admin/root/signing authority. DP:3 credential exposure. CH:4 / boundary_crossing: the recovered shared secret bridges from device-extraction to a reusable authority across the fleet. SR:4 the credential is shared/hard-coded across the entire fleet (portable secret). SX:3 reusable deployment-wide but each device still needs local/serial access to apply. OR:4 a hard-coded secret cannot be rotated without firmware update across the fleet -> recovery_needs_fleet_action. EV:2 report-backed.

Published baseline

  • v3.1 9.3 CRITICAL — CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — Baxter/Product Security via NVD

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0005 (“Baxter Life2000 hard-coded clinician credentials”), paths.cfse.ai/CPATH-2026-0005 (published 2026-06-03).