Physical/safety
DEVICE_CONTROL_SAFETY
Vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE CPATH-2026-0006 · MEDICAL IOT
DEVICE_CONTROL_SAFETY Physical/safety · Evidence EV:2 (report-backed) · Liveness ACTIVE | CPATH ID | CPATH-2026-0006 |
| CVE(s) | CVE-2024-12248 |
| Device / class | Contec CMS8000 out-of-bounds write via UDP (MEDICAL IOT) |
| Vendor | Contec |
| Dominant consequence | DEVICE_CONTROL_SAFETY (Physical/safety) |
| Paths verdict | EMERGENCY (worst of 2 paths) |
| Published baseline | v4.0 9.3 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X · CISA/ICS-CERT via NVDv3.1 9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H · CISA/ICS-CERT via NVD |
| Baseline relationship | ▼ Paths higher |
| Consequence dimension(s) | #1 #2 #7 #8 (what these mean) |
| Scored | 2026-06-03 · CFSE Consequence Paths v1.0-candidate · validation: provisional |
| Baseline confidence | high |
Consequence Paths
Physical/safety
DEVICE_CONTROL_SAFETYCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE Physical/safety
DEVICE_AVAILABILITYCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:4/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE CFSE Consequence Paths assesses Contec CMS8000 out-of-bounds write via UDP at EMERGENCY — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.
Contec CMS8000 out-of-bounds write via UDP. Reported attack vector: Network.
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → EMERGENCYCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE
Exposure EX=3 (execution complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
DEVICE_AVAILABILITY → EMERGENCYCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:4/DP:0/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:ACTIVE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=ELEVATED · AT=CRITICAL → base EMERGENCY · uplift recall-class recovery → assessed EMERGENCY.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — CISA/ICS-CERT via NVDCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — CISA/ICS-CERT via NVDThe published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
CFSE Consequence Paths Registry v1.0-candidate, entry CPATH-2026-0006 (“Contec CMS8000 out-of-bounds write via UDP”), paths.cfse.ai/CPATH-2026-0006 (published 2026-06-03).