CPATH-2026-0007 · Wearable health

Qardio BLE unauthenticated DoS (startMeasurement flood)

A dominant device availability and recovery path connects the public security record to a provisional ELEVATED consequence band.

Candidate bandELEVATED
Dominant pathDevice availability and recovery

This path is explicitly dominant because it reaches the record's highest candidate band, ELEVATED.

Causal model

What has to happen for this consequence to hold?

1 candidate path · explicit source, inference, and assumption boundaries.

Recovery · Dominant path

Device availability and recovery

Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.

ELEVATED
  1. accessSource-backed

    Proximity or local access

    BLE proximity (~10m), no pairing and auth (local-net and proximity position).

    EvidenceNVD

  2. boundaryModel inference

    Single bounded transition

    Limited chaining - crosses physical and device boundary but does not transfer authority across domains.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Operational safety effect

    Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device availability and recovery

    Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Routine local recovery

    User-visible, recoverable by disconnect and battery removal, no fleet action.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

BLE proximity (~10m), no pairing and auth (local-net and proximity position).

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A short BLE script can connect and repeatedly invoke the measurement command; no memory-corruption exploit or paired session is required.

Source-backedNVD
ExposureEX 2
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.

Model inference
Data / perceptionDP 1
Low-sensitivity state

Minor and low-sensitivity data exposure.

Model inference
AuthorityAT 2
Bounded function authority

Bounded command authority over the cuff (startMeasurement) - no administrator and firmware and trust-root control.

Model inference
Scale and recovery
ChainabilityCH 1
Single bounded transition

Limited chaining - crosses physical and device boundary but does not transfer authority across domains.

Model inference
Reuse scaleSR 3
Portable product-class technique

The unauthenticated-write method and script is portable and reusable across any unit.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each request flood requires Bluetooth proximity to one target device; it cannot execute remotely across a fleet.

Operational assumption
Recovery burdenOR 1
Routine local recovery

User-visible, recoverable by disconnect and battery removal, no fleet action.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Historical
Historical condition

The condition is retained as a historical case rather than a claim of current field exposure.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandELEVATED
  2. No adjustment

    The ELEVATED base band remains final because no separate cap or systemic uplift applies. Repeated unauthenticated measurement commands can force cuff inflation and block legitimate readings, causing discomfort and a bounded monitoring outage rather than severe injury.

  3. Final candidate bandELEVATED
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:2/DP:1/AT:2/CH:1/SR:3/SX:2/OR:1/EV:3/LS:HISTORICALRead the scoring method →

Triage implication

Verify the recovery transition before acting on the band.

Validate each modeled transition and recovery assumption before using the candidate band as a remediation decision.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is lower
Baseline confidencehigh
Scored2026-06-03
v4.0 · 6.1 MEDIUMCISA/ICS-CERT via NVD
CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
v3.1 · 7.1 HIGHCISA/ICS-CERT via NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Qardio BLE unauthenticated DoS (startMeasurement flood) at ELEVATED — the worst of 1 risk path (safety). The dominant consequence is denial of a device function.

Vulnerability

Qardio BLE unauthenticated DoS (startMeasurement flood). Reported attack vector: Adjacent.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_AVAILABILITYELEVATED

CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:4/EX:2/PH:2/DP:1/AT:2/CH:1/SR:3/SX:2/OR:1/EV:3/LS:HISTORICAL

Exposure EX=2 (reachability-bound) · bands PH=ELEVATED · DP=ELEVATED · AT=ELEVATED → base ELEVATED → assessed ELEVATED.

  • BLE proximity (~10m), no pairing/auth, so RE:2 (local-net/proximity position). EC:4 because despite CVSS AC:H the practical exploit is a simple connect-and-write bleak script (single-request commodity). AT:2: bounded command authority over the cuff (startMeasurement) - no admin/firmware/trust-root control. PH:2: repeated cuff inflation is discomfort/nuisance and blocks legitimate clinical monitoring (availability disruption) but no credible severe injury or wrong-therapy. DP:1: minor/low-sensitivity data exposure. CH:1: limited chaining - crosses physical/device boundary (boundary_crossing=true) but does not transfer authority across domains. SR:3: the unauthenticated-write method/script is portable and reusable across any unit. SX:2: requires per-device BLE proximity, not remote/fleet-scale. OR:1: user-visible, recoverable by disconnect/battery removal, no fleet action. EV:3: reproduced.
  • perception_feeds_action — false (no perception drives action).
  • active_exploitation — false (no in-the-wild evidence; HISTORICAL).

Published baseline

  • v4.0 6.1 MEDIUM — CVSS:4.0/AV:A/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X — CISA/ICS-CERT via NVD
  • v3.1 7.1 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H — CISA/ICS-CERT via NVD

The published baseline above is retained for source review. The registry records the reachable consequence path rather than treating the baseline score as the primary registry frame.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0007 (“Qardio BLE unauthenticated DoS (startMeasurement flood)”), paths.cfse.ai/CPATH-2026-0007 (published 2026-06-03).