Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Perception · Co-dominant path
Perception-to-action
The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.
Proximity or local access
Network intermediary control position on the control path.
EvidenceNo direct citation — inspect the declared inference or assumption.
Reusable multi-stage bridge
The attack crosses from the control network into robot motion and then into the physical surgical environment.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception-to-action
The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Operators can abort and re-establish the control link, but restoring trustworthy operation also requires protecting the command channel from repeated interception.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Network intermediary control position on the control path.
- Execution complexity
EC 2 - Specialist multi-step technique
The attacker must first intercept the teleoperation link; once on path, command or feedback injection is straightforward and repeatable.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Manipulated command or feedback state directly drives a patient-manipulating robot, so false control state can create a severe procedural hazard.
- Data / perception
DP 4 - Safety-driving perception or intimate data
The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.
- Authority
AT 3 - Administrative or command authority
The injected packet reaches command authority over robot motion, but not operating-system root or the firmware signing boundary.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
The attack crosses from the control network into robot motion and then into the physical surgical environment.
- Reuse scale
SR 3 - Portable product-class technique
The protocol weakness can recur wherever the same unauthenticated control channel is deployed, but it does not expose a shared key.
- Execution scale
SX 2 - Proximity-bound repetition
Each attack remains tied to one reachable control link and deployment; there is no fleet mechanism.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Operators can abort and re-establish the control link, but restoring trustworthy operation also requires protecting the command channel from repeated interception.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Historical - Historical condition
The condition is retained as a historical case rather than a claim of current field exposure.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. The attacker changes the live command and feedback state that the operator and robot use to coordinate surgical motion.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:4/DP:4/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →Safety · Co-dominant path
Device-control safety
Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.
Proximity or local access
Network intermediary control position.
EvidenceNo direct citation — inspect the declared inference or assumption.
Reusable multi-stage bridge
The attack crosses from an intercepted network control channel into robot motion at the patient boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Operators must restore the trusted control link, verify robot state, and determine whether the interrupted procedure can safely continue.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
Network intermediary control position.
- Execution complexity
EC 2 - Specialist multi-step technique
Reproducible intermediary control, simple injection once positioned.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.
- Data / perception
DP 3 - Sensitive device or personal data
The intercepted channel carries the live command and control state used to move the surgical robot.
- Authority
AT 3 - Administrative or command authority
The injected packet reaches command authority over robot motion, but not operating-system root or the firmware signing boundary.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
The attack crosses from an intercepted network control channel into robot motion at the patient boundary.
- Reuse scale
SR 3 - Portable product-class technique
The injection method can be reused wherever the same unprotected teleoperation protocol is deployed.
- Execution scale
SX 2 - Proximity-bound repetition
Each attack remains tied to one reachable robot-control session and does not provide a fleet execution mechanism.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Operators must restore the trusted control link, verify robot state, and determine whether the interrupted procedure can safely continue.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Historical - Historical condition
The condition is retained as a historical case rather than a claim of current field exposure.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Injected surgical-robot commands can produce unintended instrument motion and create a credible risk of patient injury.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →Recovery · Co-dominant path
Device availability and recovery
Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.
Proximity or local access
The attacker needs an on-path position on the robot’s control network to inject or suppress session traffic.
EvidenceNo direct citation — inspect the declared inference or assumption.
One cross-boundary bridge
The packet crosses from the control network into the robot’s safety state, but it does not create a broader reusable authority chain.
EvidenceNo direct citation — inspect the declared inference or assumption.
Credible safety consequence
Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device availability and recovery
Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Operators must restore the trusted control link, verify robot state, and decide whether the interrupted procedure can safely resume.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker needs an on-path position on the robot’s control network to inject or suppress session traffic.
- Execution complexity
EC 3 - Reproducible exploit workflow
Standard once positioned but notably efficient (single packet).
- Exposure
EX 2 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 3 - Credible safety consequence
Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.
- Data / perception
DP 1 - Low-sensitivity state
This path interrupts the control session and does not depend on reading or changing patient data.
- Authority
AT 2 - Bounded function authority
Triggering the emergency stop reaches one bounded safety function but does not grant general command, administrator, or firmware authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The packet crosses from the control network into the robot’s safety state, but it does not create a broader reusable authority chain.
- Reuse scale
SR 3 - Portable product-class technique
The denial method is reusable across deployments that use the same unprotected teleoperation protocol.
- Execution scale
SX 2 - Proximity-bound repetition
Each interruption requires an on-path position against one active teleoperation link.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Operators must restore the trusted control link, verify robot state, and decide whether the interrupted procedure can safely resume.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
source citation pending public URL supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Historical - Historical condition
The condition is retained as a historical case rather than a claim of current field exposure.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Halting the robot mid-procedure can disrupt care and reduce the operating margin, but the emergency stop is a fail-safe rather than attacker-directed motion.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:3/EX:2/PH:3/DP:1/AT:2/CH:2/SR:3/SX:2/OR:2/EV:3/LS:HISTORICALRead the scoring method →Triage implication
Verify the perception transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
At least one citation still lacks a public URL; that gap keeps this record provisional.
- othersource citation pending public URL
source citation pending public URL · public URL pending
Published baseline
Keep exploit severity and consequence reasoning distinct.
No public baseline score is available for this case.
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse at CRITICAL — the worst of 3 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.
Vulnerability
Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse. Reported attack vector: Network (man-in-the-middle on teleoperation link).
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_TO_ACTION → CRITICAL
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:2/EC:2/EX:2/PH:4/DP:4/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL
Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=CRITICAL · AT=HIGH → base CRITICAL → assessed CRITICAL.
- Intention-modification: MITM on the unauthenticated/unencrypted teleoperation link lets the attacker read and alter the command/feedback stream so the corrupted perception loop between surgeon and robot drives unintended actuation.
- RE2 — (network MITM position on the control path; demonstrated on public/shared networks, not internet-default and not victim physical).
- EC2 — advanced-but-reproducible MITM, but trivial once positioned.
- AT3 — control-channel/command authority over robot, not OS root or signing root.
- PH4 — and DP4 because the manipulated feedback/command state is safety-relevant world/control state on a patient-manipulating robot;
- perception_feeds_action — true.
- CH3 — crosses console/network/device/physical/safety boundaries.
- SR3 — protocol-level weakness reuses across deployments using the same unprotected protocol but is not a shared key/artifact.
- SX2 — per-link/per-deployment proximity, no fleet mechanism.
- EV3 — reproduced (DSN 2015).
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL
Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL → assessed CRITICAL.
- Full hijacking: attacker gains effective control authority over robot motion without credentials, overriding/ignoring operator inputs to drive dangerous actuation against a patient.
- RE2 — network MITM position.
- EC2 — reproducible MITM, simple injection once positioned.
- AT3 — control/command authority (no root-of-trust or signing key compromised).
- PH4 — credible patient injury from unintended/maliciously commanded motion;
- perception_feeds_action — true since the hijacked command stream directly causes safety-relevant physical action.
- DP3 — control/command state.
- CH3 — and boundary_crossing across network/device/physical/safety.
- SR3 — protocol-class reuse.
- SX2 — per-link, no demonstrated fleet execution.
- OR2 — recovery is operational (regain link, abort).
- EV3 — reproduced.
DEVICE_AVAILABILITY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_AVAILABILITY/RE:2/EC:3/EX:2/PH:4/DP:1/AT:2/CH:2/SR:3/SX:2/OR:2/EV:3/LS:HISTORICAL
Exposure EX=2 (reachability-bound) · bands PH=CRITICAL · DP=ELEVATED · AT=ELEVATED → base CRITICAL → assessed CRITICAL.
- E-stop abuse: a single unauthenticated packet triggers the robot’s own emergency-stop to deny operation mid-procedure.
- RE2 — network MITM/on-path position.
- EC3 — standard once positioned but notably efficient (single packet); not EC4 because it still needs an on-path/injection position.
- AT2 — abuse of a bounded safety/availability control rather than full command authority.
- PH3 — safety-margin reduction: aborting/halting mid-procedure is disruptive and can reduce safety margin but is the platform’s fail-safe rather than dangerous actuation, so not PH4.
- DP1 — negligible data impact.
- CH2 — crosses network/device/safety boundary, limited chainability.
- SR3 — protocol-class reuse.
- SX2 — per-link.
- OR2 — operational recovery (regain link, abort/restart).
- EV3 — reproduced.
Published baseline
No public baseline score has been published for this finding. It belongs to a perception/control harm class that is often outside published vulnerability-scoring coverage. The registry records the reachable consequence path for review.
Sources
- source citation pending public URL
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0028 (“Teleoperated surgical robot (Raven II) command hijacking & E-stop abuse”), paths.cfse.ai/CPATH-2026-0028 (published 2026-06-03).