Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Safety · Co-dominant path
Device-control safety
Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.
Proximity or local access
The attacker must be within range of the pump's proprietary radio; the interface is not reachable from the public internet.
EvidenceNVD
Reusable multi-stage bridge
The unauthenticated radio message crosses into pump command handling and then into insulin delivery to the patient.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
The mitigation program required patient guidance and migration or replacement of affected legacy pump models.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must be within range of the pump's proprietary radio; the interface is not reachable from the public internet.
- Execution complexity
EC 2 - Specialist multi-step technique
Issuing delivery commands requires specialist radio equipment and protocol knowledge, but researchers reproduced the workflow.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.
- Data / perception
DP 3 - Sensitive device or personal data
The command path carries dosing, treatment, and pump operational state used to control insulin delivery.
- Authority
AT 3 - Administrative or command authority
Without authentication, an in-range transmitter can issue commands as a legitimate controller, but it does not gain a signing key.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
The unauthenticated radio message crosses into pump command handling and then into insulin delivery to the patient.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same unauthenticated protocol behavior is shared across the affected MiniMed and Paradigm product family.
- Execution scale
SX 2 - Proximity-bound repetition
Each pump must be approached within radio range; the technique does not provide remote fleet control.
- Recovery burden
OR 4 - Fleet action or replacement
The mitigation program required patient guidance and migration or replacement of affected legacy pump models.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →Privacy · Co-dominant path
Data privacy
Radio traffic reveals patient treatment, dosing, and pump operational state.
Proximity or local access
The attacker must be near the pump and able to receive its proprietary radio transmissions.
EvidenceNVD
One cross-boundary bridge
The unauthenticated radio channel moves sensitive treatment state outside the pump boundary.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
Radio traffic reveals patient treatment, dosing, and pump operational state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
Radio traffic reveals patient treatment, dosing, and pump operational state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Eliminating the legacy protocol exposure requires the product-family mitigation or replacement program, not a session reset.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must be near the pump and able to receive its proprietary radio transmissions.
- Execution complexity
EC 2 - Specialist multi-step technique
Reading the traffic requires the same specialist protocol and radio setup used for the command path.
- Exposure
EX 2 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 0 - No direct physical effect
Passive interception does not alter insulin delivery; therapy manipulation is assessed in the separate safety path.
- Data / perception
DP 3 - Sensitive device or personal data
Radio traffic reveals patient treatment, dosing, and pump operational state.
- Authority
AT 2 - Bounded function authority
This path is limited to reading exposed radio data and does not grant configuration or firmware authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The unauthenticated radio channel moves sensitive treatment state outside the pump boundary.
- Reuse scale
SR 4 - Shared fleet-wide primitive
One protocol implementation can be reused to observe affected pumps across the same product family.
- Execution scale
SX 2 - Proximity-bound repetition
Each interception requires proximity to an individual patient and pump.
- Recovery burden
OR 4 - Fleet action or replacement
Eliminating the legacy protocol exposure requires the product-family mitigation or replacement program, not a session reset.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Mitigated - Vendor mitigation is recorded
The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Radio traffic reveals patient treatment, dosing, and pump operational state.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:HCVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVE recordsCVE-2019-10964
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED
Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.
Adjacent RF only, no internet exposure -> RE:2 (proximity/RF). Execution requires specialized RF equipment + proprietary protocol knowledge but is researcher-reproducible (AC:H) -> EC:2 advanced-but-reproducible. No auth/authz means in-range attacker issues commands as a legitimate paired controller, controlling delivery and settings = command/control authority over the device but not signing-root/OTA-root -> AT:3. Altering insulin delivery causes hypoglycemia or hyperglycemia/DKA, credibly fatal therapy mistreatment -> PH:4. Manipulated/forged dosing commands drive therapy actuation; this is command injection rather than exposed perception, but I do not mark perception_feeds_action because the consequence is direct actuation, not a perception/world-model feed (per definition, dosing command falsification is actuation control). Crosses RF/protocol -> device -> physical/safety boundaries -> boundary_crossing true, CH:3. Protocol weakness is shared across an entire product family (same unauthenticated proprietary RF), reusable knowledge -> SR:4. Not remotely scalable; per-patient proximity required -> SX:2. No software patch possible for legacy pumps; recall and hardware replacement / migration to newer models -> OR:4, recovery_needs_fleet_action true. Report-backed advisory, no in-the-wild exploitation -> EV:2, active_exploitation false.
DATA_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED
Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=ELEVATED → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.
Same adjacent-RF position and proprietary-protocol skill requirement -> RE:2, EC:2. Confidentiality rated Low (C:L): attacker can intercept and read patient/device RF data including health/device operational state -> DP:3 (health + sensitive device/dosing state). Reading-only consequence here gives bounded session/component exposure of patient data, not config/firmware control -> AT:2. No physical/safety effect on the pure-read path -> PH:0. Crosses RF -> device/app data boundary -> boundary_crossing true, CH:2. Same family-wide unauthenticated protocol enables reuse of interception technique -> SR:4. Per-patient proximity, not remotely scalable -> SX:2. No patch; legacy hardware replacement -> OR:4, recovery_needs_fleet_action true. Report-backed -> EV:2, not exploited in wild -> active_exploitation false.
Published baseline
- v3.1 7.1 HIGH —
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H— CISA/ICS-CERT via NVD - v3.0 8.8 HIGH —
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H— NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0036 (“Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control”), paths.cfse.ai/CPATH-2026-0036 (published 2026-06-03).