Physical/safety
DEVICE_CONTROL_SAFETY
Vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE CPATH-2026-0005 · MEDICAL IOT
ACCOUNT_AUTHORITY authority · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE | CPATH ID | CPATH-2026-0005 |
| CVE(s) | CVE-2024-48971 |
| Device / class | Baxter Life2000 hard-coded clinician credentials (MEDICAL IOT) |
| Vendor | Baxter |
| Dominant consequence | ACCOUNT_AUTHORITY (authority) |
| Paths verdict | CRITICAL (worst of 2 paths) |
| Published baseline | v3.1 9.3 CRITICAL CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · Baxter/Product Security via NVD |
| Baseline relationship | ◀▶ comparable |
| Consequence dimension(s) | #1 #2 #7 #8 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
Physical/safety
DEVICE_CONTROL_SAFETYCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE authority
ACCOUNT_AUTHORITYCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE CFSE Consequence Paths assesses Baxter Life2000 hard-coded clinician credentials at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is privileged account or control authority.
Baxter Life2000 hard-coded clinician credentials. Reported attack vector: Local.
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → HIGHCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=2 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.
ACCOUNT_AUTHORITY → CRITICALCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=3 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.
Hard-coded Clinician / Serial-Number Clinician passwords extracted from device firmware (RE:3 attacker uses own device/firmware copy, no victim hardware needed; AV:L but extractable from any unit). Extraction is straightforward once firmware/device available (EC:4). AT:2 because it grants a bounded clinician-level account, not admin/root/signing authority. DP:3 credential exposure. CH:4 / boundary_crossing: the recovered shared secret bridges from device-extraction to a reusable authority across the fleet. SR:4 the credential is shared/hard-coded across the entire fleet (portable secret). SX:3 reusable deployment-wide but each device still needs local/serial access to apply. OR:4 a hard-coded secret cannot be rotated without firmware update across the fleet -> recovery_needs_fleet_action. EV:2 report-backed.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — Baxter/Product Security via NVDThe published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0005 (“Baxter Life2000 hard-coded clinician credentials”), paths.cfse.ai/CPATH-2026-0005 (published 2026-06-03).