CPATH-2026-0006 · Medical IoT

Contec CMS8000 out-of-bounds write via UDP

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsDevice-control safety + Device availability and recovery

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Single unauthenticated UDP datagram, network-reachable (the same local network and on-path) is default and internet-style exposure.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    A network packet crosses into code execution in the monitor process and then into the clinical display and alarm functions used for care.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    No patch, CISA says remove from network to fleet-level remediation.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Single unauthenticated UDP datagram, network-reachable (the same local network and on-path) is default and internet-style exposure.

Source-backedNVD
Execution complexityEC 3
Reproducible exploit workflow

Out-of-bounds write with controllable offset, without authentication and handshake — standard researcher exploitation workflow.

Source-backedNVD
ExposureEX 3
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Vitals are health and sensitive operational state.

Model inference
AuthorityAT 3
Administrative or command authority

Code execution in monolithic root monitor process is full device-control and administrator command authority, but not a signing and firmware-update and trust-root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

A network packet crosses into code execution in the monitor process and then into the clinical display and alarm functions used for care.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

Identical firmware across all units and rebrands.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remotely reachable on a flat network, no per-device physical access.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

No patch, CISA says remove from network to fleet-level remediation.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. Systemic uplift

    The CRITICAL base band rises to EMERGENCY because the same remote code-execution primitive applies across affected monitors and CISA’s removal guidance makes recovery a fleet-wide operational action.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVERead the scoring method →

Recovery · Co-dominant path

Device availability and recovery

Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The malformed network request can reach any affected monitor whose vulnerable service is exposed to the attacker.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    Contributes to a denial chain and crosses network to device boundary but is less of a reusable cross-domain authority bridge than full remote code execution.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    No patch, removal from network required.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The malformed network request can reach any affected monitor whose vulnerable service is exposed to the attacker.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

One malformed UDP datagram can crash or hang the monolithic monitor process; reliable code execution is not required for this availability path.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.

Model inference
Data / perceptionDP 0
No data consequence

A crash exposes no data.

Model inference
AuthorityAT 2
Bounded function authority

Crashing the process is bounded component and session disruption, not configuration and command authority.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

Contributes to a denial chain and crosses network to device boundary but is less of a reusable cross-domain authority bridge than full remote code execution.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same request can be reused across affected monitors that run the vulnerable service.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Remote, fleet-scale on flat network.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

No patch, removal from network required.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Active
Active condition at scoring time

The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVERead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v4.0 · 9.3 CRITICALCISA/ICS-CERT via NVD
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 9.8 CRITICALCISA/ICS-CERT via NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Contec CMS8000 out-of-bounds write via UDP at EMERGENCY — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Contec CMS8000 out-of-bounds write via UDP. Reported attack vector: Network.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE

Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

  • RE4 — single unauthenticated UDP datagram, network-reachable (same-VLAN/on-path) is default/internet-style exposure.
  • EC3 — OOB write with controllable offset, no auth/handshake — standard researcher exploitation workflow.
  • AT3 — code exec in monolithic root monitor process is full device-control/admin command authority, but not a signing/OTA/trust-root, so not 4.
  • PH4 — a patient monitor under attacker control can falsify vitals or suppress alarms -> credible wrong-therapy/missed-event injury.
  • DP3 — vitals are health/sensitive operational state.
  • perception_feeds_action — true: monitor readings drive clinical decisions/therapy.
  • CH4 — + boundary_crossing: RCE bridges network->device->safety domain, reusable.
  • SR4 — identical firmware across all units and rebrands.
  • SX4 — remotely reachable on a flat network, no per-device physical access.
  • OR4 — no patch, CISA says remove from network -> fleet-level remediation.
  • EV2 — report-backed advisory, not independently reproduced here.

DEVICE_AVAILABILITYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:4/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=ELEVATED · AT=CRITICAL → base EMERGENCY · uplift recall-class recovery → assessed EMERGENCY.

  • RE4 — same unauthenticated network-reachable UDP datagram.
  • EC4 — triggering an OOB write to crash/hang the monolithic process is trivial — a single malformed datagram, easier than reliable RCE.
  • AT2 — crashing the process is bounded component/session disruption, not config/command authority.
  • PH2 — loss of monitoring availability disrupts the workflow/alarming but is degraded-monitoring rather than direct dangerous actuation (clinician can notice an offline monitor).
  • DP0 — a crash exposes no data.
  • CH3 — contributes to a denial chain and crosses network->device boundary but is less of a reusable cross-domain authority bridge than full RCE.
  • SR4 — same firmware fleet-wide.
  • SX4 — remote, fleet-scale on flat network.
  • OR4 — no patch, removal from network required.
  • EV2 — report-backed.

Published baseline

  • v4.0 9.3 CRITICAL — CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — CISA/ICS-CERT via NVD
  • v3.1 9.8 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — CISA/ICS-CERT via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0006 (“Contec CMS8000 out-of-bounds write via UDP”), paths.cfse.ai/CPATH-2026-0006 (published 2026-06-03).