← Registry

CPATH-2026-0005 · MEDICAL IOT

Baxter Life2000 hard-coded clinician credentials

Provisional. Candidate score (CFSE Consequence Paths 1.0-candidate); pending independent review. Treat as a structured second opinion, not a final rating.
Paths CRITICAL Dominant consequence ACCOUNT_AUTHORITY authority · Evidence EV:2 (report-backed) · Liveness PATCH_AVAILABLE
CPATH IDCPATH-2026-0005
CVE(s)CVE-2024-48971
Device / classBaxter Life2000 hard-coded clinician credentials (MEDICAL IOT)
VendorBaxter
Dominant consequenceACCOUNT_AUTHORITY (authority)
Paths verdictCRITICAL (worst of 2 paths)
Published baseline
v3.1 9.3 CRITICAL CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H · Baxter/Product Security via NVD
Baseline relationship◀▶ comparable
Consequence dimension(s)#1 #2 #7 #8 (what these mean)
Scored2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional
Baseline confidencehigh

Consequence Paths

Paths Assessment

Physical/safety

DEVICE_CONTROL_SAFETY

HIGH
Reachability RE:2
Complexity EC:4
Consequence DEVICE_CONTROL_SAFETY
Scale SR:4 / SX:2
Verdict HIGH
Reachability 2
Complexity 4
Exposure 2
Physical / safety 3
Data / perception 3
Authority 3
Chainability 4
Reuse scale 4
Execution scale 2
Recovery 4
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE

authority

ACCOUNT_AUTHORITY

CRITICAL
Reachability RE:3
Complexity EC:4
Consequence ACCOUNT_AUTHORITY
Scale SR:4 / SX:3
Verdict CRITICAL
Reachability 3
Complexity 4
Exposure 3
Physical / safety 3
Data / perception 3
Authority 2
Chainability 4
Reuse scale 4
Execution scale 3
Recovery 4
Evidence EV:2 · report-backed
Liveness PATCH_AVAILABLE
Vector CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE

Assessment

CFSE Consequence Paths assesses Baxter Life2000 hard-coded clinician credentials at CRITICAL — the worst of 2 risk paths (safety, authority). The dominant consequence is privileged account or control authority.

Vulnerability

Baxter Life2000 hard-coded clinician credentials. Reported attack vector: Local.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYHIGH

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:4/EX:2/PH:3/DP:3/AT:3/CH:4/SR:4/SX:2/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=2 (reachability-bound) · bands PH=HIGH · DP=HIGH · AT=HIGH → base HIGH · uplift recall-class recovery → assessed HIGH.

ACCOUNT_AUTHORITYCRITICAL

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:3/EC:4/EX:3/PH:3/DP:3/AT:2/CH:4/SR:4/SX:3/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=3 (reachability-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.

Hard-coded Clinician / Serial-Number Clinician passwords extracted from device firmware (RE:3 attacker uses own device/firmware copy, no victim hardware needed; AV:L but extractable from any unit). Extraction is straightforward once firmware/device available (EC:4). AT:2 because it grants a bounded clinician-level account, not admin/root/signing authority. DP:3 credential exposure. CH:4 / boundary_crossing: the recovered shared secret bridges from device-extraction to a reusable authority across the fleet. SR:4 the credential is shared/hard-coded across the entire fleet (portable secret). SX:3 reusable deployment-wide but each device still needs local/serial access to apply. OR:4 a hard-coded secret cannot be rotated without firmware update across the fleet -> recovery_needs_fleet_action. EV:2 report-backed.

Published baseline

The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.

Sources

Score it yourself in the calculator Review this score
Cite this entry: CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0005 (“Baxter Life2000 hard-coded clinician credentials”), paths.cfse.ai/CPATH-2026-0005 (published 2026-06-03).