Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.
Network-reachable without prior access
Single unauthenticated UDP datagram, network-reachable (the same local network and on-path) is default and internet-style exposure.
EvidenceNVD
Cross-domain authority chain
A network packet crosses into code execution in the monitor process and then into the clinical display and alarm functions used for care.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
No patch, CISA says remove from network to fleet-level remediation.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Single unauthenticated UDP datagram, network-reachable (the same local network and on-path) is default and internet-style exposure.
- Execution complexity
EC 3 - Reproducible exploit workflow
Out-of-bounds write with controllable offset, without authentication and handshake — standard researcher exploitation workflow.
- Exposure
EX 3 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Remote code execution on the monitor can falsify displayed vitals or suppress alarms, creating a credible missed-event or wrong-treatment risk.
- Data / perception
DP 3 - Sensitive device or personal data
Vitals are health and sensitive operational state.
- Authority
AT 3 - Administrative or command authority
Code execution in monolithic root monitor process is full device-control and administrator command authority, but not a signing and firmware-update and trust-root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
A network packet crosses into code execution in the monitor process and then into the clinical display and alarm functions used for care.
- Reuse scale
SR 4 - Shared fleet-wide primitive
Identical firmware across all units and rebrands.
- Execution scale
SX 4 - Remote fleet-scale execution
Remotely reachable on a flat network, no per-device physical access.
- Recovery burden
OR 4 - Fleet action or replacement
No patch, CISA says remove from network to fleet-level remediation.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandCRITICAL
- Systemic uplift
The CRITICAL base band rises to EMERGENCY because the same remote code-execution primitive applies across affected monitors and CISA’s removal guidance makes recovery a fleet-wide operational action.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVERead the scoring method →Recovery · Co-dominant path
Device availability and recovery
Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.
Network-reachable without prior access
The malformed network request can reach any affected monitor whose vulnerable service is exposed to the attacker.
EvidenceNVD
Reusable multi-stage bridge
Contributes to a denial chain and crosses network to device boundary but is less of a reusable cross-domain authority bridge than full remote code execution.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device availability and recovery
Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
No patch, removal from network required.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The malformed network request can reach any affected monitor whose vulnerable service is exposed to the attacker.
- Execution complexity
EC 4 - Straightforward operation
One malformed UDP datagram can crash or hang the monolithic monitor process; reliable code execution is not required for this availability path.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.
- Data / perception
DP 0 - No data consequence
A crash exposes no data.
- Authority
AT 2 - Bounded function authority
Crashing the process is bounded component and session disruption, not configuration and command authority.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
Contributes to a denial chain and crosses network to device boundary but is less of a reusable cross-domain authority bridge than full remote code execution.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same request can be reused across affected monitors that run the vulnerable service.
- Execution scale
SX 4 - Remote fleet-scale execution
Remote, fleet-scale on flat network.
- Recovery burden
OR 4 - Fleet action or replacement
No patch, removal from network required.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Active - Active condition at scoring time
The public record did not establish a complete mitigation at scoring time; field exploitation is stated only where a cited source supports it.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Taking a monitor offline interrupts surveillance and alarm workflows; staff can detect the outage, so this is degraded monitoring rather than attacker-directed therapy.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2024-12248
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Contec CMS8000 out-of-bounds write via UDP at EMERGENCY — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Contec CMS8000 out-of-bounds write via UDP. Reported attack vector: Network.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE
Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
- RE4 — single unauthenticated UDP datagram, network-reachable (same-VLAN/on-path) is default/internet-style exposure.
- EC3 — OOB write with controllable offset, no auth/handshake — standard researcher exploitation workflow.
- AT3 — code exec in monolithic root monitor process is full device-control/admin command authority, but not a signing/OTA/trust-root, so not 4.
- PH4 — a patient monitor under attacker control can falsify vitals or suppress alarms -> credible wrong-therapy/missed-event injury.
- DP3 — vitals are health/sensitive operational state.
- perception_feeds_action — true: monitor readings drive clinical decisions/therapy.
- CH4 — + boundary_crossing: RCE bridges network->device->safety domain, reusable.
- SR4 — identical firmware across all units and rebrands.
- SX4 — remotely reachable on a flat network, no per-device physical access.
- OR4 — no patch, CISA says remove from network -> fleet-level remediation.
- EV2 — report-backed advisory, not independently reproduced here.
DEVICE_AVAILABILITY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:4/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=ELEVATED · AT=CRITICAL → base EMERGENCY · uplift recall-class recovery → assessed EMERGENCY.
- RE4 — same unauthenticated network-reachable UDP datagram.
- EC4 — triggering an OOB write to crash/hang the monolithic process is trivial — a single malformed datagram, easier than reliable RCE.
- AT2 — crashing the process is bounded component/session disruption, not config/command authority.
- PH2 — loss of monitoring availability disrupts the workflow/alarming but is degraded-monitoring rather than direct dangerous actuation (clinician can notice an offline monitor).
- DP0 — a crash exposes no data.
- CH3 — contributes to a denial chain and crosses network->device boundary but is less of a reusable cross-domain authority bridge than full RCE.
- SR4 — same firmware fleet-wide.
- SX4 — remote, fleet-scale on flat network.
- OR4 — no patch, removal from network required.
- EV2 — report-backed.
Published baseline
- v4.0 9.3 CRITICAL —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— CISA/ICS-CERT via NVD - v3.1 9.8 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— CISA/ICS-CERT via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0006 (“Contec CMS8000 out-of-bounds write via UDP”), paths.cfse.ai/CPATH-2026-0006 (published 2026-06-03).