Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.
Cross-domain authority chain
Chains across network to device to control-plane and is noted to chain to firmware persistence, crossing boundaries.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery requires patching the vulnerable service and verifying affected stations before returning them to operation.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Unauthenticated network packets to the TLP20 port.
- Execution complexity
EC 3 - Reproducible exploit workflow
Stack overflow with return-address control on a flat-memory RTOS with weak mitigations is a standard-to-advanced researcher workflow.
- Exposure
EX 3 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.
- Data / perception
DP 3 - Sensitive device or personal data
Remote code execution exposes operational and firmware-relevant state.
- Authority
AT 3 - Administrative or command authority
Code execution in the station controller can govern routing and pneumatic-tube behavior, but it does not provide a vendor firmware-signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Chains across network to device to control-plane and is noted to chain to firmware persistence, crossing boundaries.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same malformed message can be reused against affected stations that run the vulnerable Translogic service.
- Execution scale
SX 4 - Remote fleet-scale execution
Network-reachable, no per-device physical access needed.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery requires patching the vulnerable service and verifying affected stations before returning them to operation.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLERead the scoring method →Recovery · Co-dominant path
Device availability and recovery
Loss of the station controller disrupts hospital logistics availability with no severe harm.
Network-reachable without prior access
The malformed network message can reach any affected station whose vulnerable service is exposed to the attacker.
EvidenceNVD
One cross-boundary bridge
Chains less than full remote code execution, but still crosses network to device boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Operational safety effect
Loss of the station controller disrupts hospital logistics availability with no severe harm.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device availability and recovery
Loss of the station controller disrupts hospital logistics availability with no severe harm.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Recovery requires patching or restarting affected stations and confirming that transport service has been restored.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The malformed network message can reach any affected station whose vulnerable service is exposed to the attacker.
- Execution complexity
EC 4 - Straightforward operation
A single malformed packet can crash the controller; the attacker does not need to turn the overflow into reliable code execution.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 2 - Operational safety effect
Loss of the station controller disrupts hospital logistics availability with no severe harm.
- Data / perception
DP 1 - Low-sensitivity state
Data and perception minimal (operational).
- Authority
AT 2 - Bounded function authority
Availability loss bounds the consequence to the device and component.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
Chains less than full remote code execution, but still crosses network to device boundary.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same vulnerable parser is present across affected station controllers, so the crash method can be repeated.
- Execution scale
SX 4 - Remote fleet-scale execution
Remotely reachable across stations.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Recovery requires patching or restarting affected stations and confirming that transport service has been restored.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Loss of the station controller disrupts hospital logistics availability with no severe harm.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:1/AT:2/CH:2/SR:4/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2021-37164
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Swisslog Translogic TLP20 tcpTxThread stack overflow at CRITICAL — the worst of 2 risk paths (safety). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Swisslog Translogic TLP20 tcpTxThread stack overflow. Reported attack vector: Network.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:3/EX:3/PH:2/DP:3/AT:3/CH:4/SR:4/SX:4/OR:3/EV:2/LS:PATCH_AVAILABLE
Exposure EX=3 (execution complexity-bound) · bands PH=HIGH · DP=HIGH · AT=CRITICAL → base CRITICAL · uplift fleet-reachable authority → assessed CRITICAL.
Unauthenticated network packets to the TLP20 port = RE:4. Stack overflow with return-address control on a flat-memory RTOS with weak mitigations is a standard-to-advanced researcher workflow = EC:3. RCE in the station controller control plane yields full code exec controlling the pneumatic-tube logistics device = AT:3 (control/command authority over the device, but not a signing root or OTA root, so not 4). Physical/safety: this is hospital pneumatic-tube logistics (specimens/meds transport); takeover can mis-route or halt transport, but no credible direct injury or dangerous high-energy actuation is demonstrated, so PH:2. RCE exposes operational/firmware-relevant state = DP:3. Chains across network->device->control-plane and is noted to chain to firmware persistence, crossing boundaries = CH:4, boundary_crossing true. Same parser across stations = SR:4 (portable exploit). Network-reachable, no per-device physical access needed = SX:4. Recovery requires patching to 7.2.5.7 across stations but not a signing-root rotation/recall = OR:3, recovery_needs_fleet_action false. Report-backed = EV:2. Not known exploited in the wild.
DEVICE_AVAILABILITY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:4/EC:4/EX:4/PH:2/DP:1/AT:2/CH:2/SR:4/SX:4/OR:2/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=CRITICAL → base CRITICAL → assessed CRITICAL.
Pure DoS variant: same unauthenticated network reach to TLP20 port = RE:4. Crashing the controller via the overflow without needing reliable RCE is trivial/single-malformed-packet = EC:4. Loss of the station controller disrupts hospital logistics availability with no severe harm = PH:2. Availability loss bounds the consequence to the device/component = AT:2. Data/perception minimal (operational) = DP:1. Chains less than full RCE = CH:2, but still crosses network->device boundary = boundary_crossing true. Same parser everywhere = SR:4; remotely reachable across stations = SX:4. Recovery is service restart/patch, no fleet reprovision = OR:2. Report-backed = EV:2. Not exploited in the wild.
Published baseline
- v3.1 9.8 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— NVD
The published baseline above is retained for source review. Paths decomposes the consequence into authority, perception, safety, scale, and recoverability paths rather than using the baseline score as the primary registry frame.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0010 (“Swisslog Translogic TLP20 tcpTxThread stack overflow”), paths.cfse.ai/CPATH-2026-0010 (published 2026-06-03).