Causal model
What has to happen for this consequence to hold?
1 candidate path · explicit source, inference, and assumption boundaries.
Recovery · Dominant path
Device availability and recovery
Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.
Proximity or local access
BLE proximity (~10m), no pairing and auth (local-net and proximity position).
EvidenceNVD
Single bounded transition
Limited chaining - crosses physical and device boundary but does not transfer authority across domains.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device availability and recovery
Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Routine local recovery
User-visible, recoverable by disconnect and battery removal, no fleet action.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
BLE proximity (~10m), no pairing and auth (local-net and proximity position).
- Execution complexity
EC 4 - Straightforward operation
A short BLE script can connect and repeatedly invoke the measurement command; no memory-corruption exploit or paired session is required.
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.
- Data / perception
DP 1 - Low-sensitivity state
Minor and low-sensitivity data exposure.
- Authority
AT 2 - Bounded function authority
Bounded command authority over the cuff (startMeasurement) - no administrator and firmware and trust-root control.
Scale and recovery
- Chainability
CH 1 - Single bounded transition
Limited chaining - crosses physical and device boundary but does not transfer authority across domains.
- Reuse scale
SR 3 - Portable product-class technique
The unauthenticated-write method and script is portable and reusable across any unit.
- Execution scale
SX 2 - Proximity-bound repetition
Each request flood requires Bluetooth proximity to one target device; it cannot execute remotely across a fleet.
- Recovery burden
OR 1 - Routine local recovery
User-visible, recoverable by disconnect and battery removal, no fleet action.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Historical - Historical condition
The condition is retained as a historical case rather than a claim of current field exposure.
Decision trail
How the final band follows
- Base bandELEVATED
- No adjustment
The ELEVATED base band remains final because no separate cap or systemic uplift applies. Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.
- Final candidate bandELEVATED
Technical vector
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:2/DP:1/AT:2/CH:1/SR:3/SX:2/OR:1/EV:3/LS:HISTORICALRead the scoring method →Triage implication
Verify the recovery transition before acting on the band.
Validate each modeled transition and recovery assumption before using the candidate band as a remediation decision.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:HCVE recordsCVE-2025-24836
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Qardio BLE unauthenticated DoS (startMeasurement flood) at ELEVATED — the worst of 1 risk path (safety). The dominant consequence is denial of a device function.
Vulnerability
Qardio BLE unauthenticated DoS (startMeasurement flood). Reported attack vector: Adjacent.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_AVAILABILITY → ELEVATED
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:2/DP:1/AT:2/CH:1/SR:3/SX:2/OR:1/EV:3/LS:HISTORICAL
Exposure EX=2 (reachability-bound) · bands PH=ELEVATED · DP=ELEVATED · AT=ELEVATED → base ELEVATED → assessed ELEVATED.
- BLE proximity (~10m), no pairing/auth, so RE:2 (local-net/proximity position). EC:4 because despite CVSS AC:H the practical exploit is a simple connect-and-write bleak script (single-request commodity). AT:2: bounded command authority over the cuff (startMeasurement) - no admin/firmware/trust-root control. PH:2: repeated cuff inflation is discomfort/nuisance and blocks legitimate clinical monitoring (availability disruption) but no credible severe injury or wrong-therapy. DP:1: minor/low-sensitivity data exposure. CH:1: limited chaining - crosses physical/device boundary (boundary_crossing=true) but does not transfer authority across domains. SR:3: the unauthenticated-write method/script is portable and reusable across any unit. SX:2: requires per-device BLE proximity, not remote/fleet-scale. OR:1: user-visible, recoverable by disconnect/battery removal, no fleet action. EV:3: reproduced.
- perception_feeds_action — false (no perception drives action).
- active_exploitation — false (no in-the-wild evidence; HISTORICAL).
Published baseline
- v4.0 6.1 MEDIUM —
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X— CISA/ICS-CERT via NVD - v3.1 7.1 HIGH —
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H— CISA/ICS-CERT via NVD
The published baseline above is retained for source review. The registry records the reachable consequence path rather than treating the baseline score as the primary registry frame.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0007 (“Qardio BLE unauthenticated DoS (startMeasurement flood)”), paths.cfse.ai/CPATH-2026-0007 (published 2026-06-03).