CPATH-2026-0036 · Medical IoT

Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control

Two or more co-dominant consequence paths connect the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Co-dominant pathsDevice-control safety + Data privacy

These paths are co-dominant because each reaches the record's highest candidate band, CRITICAL; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Safety · Co-dominant path

Device-control safety

Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker must be within range of the pump's proprietary radio; the interface is not reachable from the public internet.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    The unauthenticated radio message crosses into pump command handling and then into insulin delivery to the patient.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    The mitigation program required patient guidance and migration or replacement of affected legacy pump models.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker must be within range of the pump's proprietary radio; the interface is not reachable from the public internet.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Issuing delivery commands requires specialist radio equipment and protocol knowledge, but researchers reproduced the workflow.

Source-backedNVD
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The command path carries dosing, treatment, and pump operational state used to control insulin delivery.

Model inference
AuthorityAT 3
Administrative or command authority

Without authentication, an in-range transmitter can issue commands as a legitimate controller, but it does not gain a signing key.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

The unauthenticated radio message crosses into pump command handling and then into insulin delivery to the patient.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same unauthenticated protocol behavior is shared across the affected MiniMed and Paradigm product family.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each pump must be approached within radio range; the technique does not provide remote fleet control.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

The mitigation program required patient guidance and migration or replacement of affected legacy pump models.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Unauthorized insulin changes can cause hypoglycemia, hyperglycemia, or ketoacidosis and can become life-threatening.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →

Privacy · Co-dominant path

Data privacy

Radio traffic reveals patient treatment, dosing, and pump operational state.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker must be near the pump and able to receive its proprietary radio transmissions.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The unauthenticated radio channel moves sensitive treatment state outside the pump boundary.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    Radio traffic reveals patient treatment, dosing, and pump operational state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    Radio traffic reveals patient treatment, dosing, and pump operational state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Eliminating the legacy protocol exposure requires the product-family mitigation or replacement program, not a session reset.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker must be near the pump and able to receive its proprietary radio transmissions.

Source-backedNVD
Execution complexityEC 2
Specialist multi-step technique

Reading the traffic requires the same specialist protocol and radio setup used for the command path.

Source-backedNVD
ExposureEX 2
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

Passive interception does not alter insulin delivery; therapy manipulation is assessed in the separate safety path.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Radio traffic reveals patient treatment, dosing, and pump operational state.

Model inference
AuthorityAT 2
Bounded function authority

This path is limited to reading exposed radio data and does not grant configuration or firmware authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The unauthenticated radio channel moves sensitive treatment state outside the pump boundary.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One protocol implementation can be reused to observe affected pumps across the same product family.

Operational assumption
Execution scaleSX 2
Proximity-bound repetition

Each interception requires proximity to an individual patient and pump.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Eliminating the legacy protocol exposure requires the product-family mitigation or replacement program, not a session reset.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Mitigated
Vendor mitigation is recorded

The record treats the path as mitigated; the historical mechanism remains useful for review and regression analysis.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Radio traffic reveals patient treatment, dosing, and pump operational state.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:0/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATEDRead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 7.1 HIGHCISA/ICS-CERT via NVD
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H
v3.0 · 8.8 HIGHNVD
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control at CRITICAL — the worst of 2 risk paths (safety, perception). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:3/CH:3/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=HIGH → base CRITICAL · uplift recall-class recovery → assessed CRITICAL.

Adjacent RF only, no internet exposure -> RE:2 (proximity/RF). Execution requires specialized RF equipment + proprietary protocol knowledge but is researcher-reproducible (AC:H) -> EC:2 advanced-but-reproducible. No auth/authz means in-range attacker issues commands as a legitimate paired controller, controlling delivery and settings = command/control authority over the device but not signing-root/OTA-root -> AT:3. Altering insulin delivery causes hypoglycemia or hyperglycemia/DKA, credibly fatal therapy mistreatment -> PH:4. Manipulated/forged dosing commands drive therapy actuation; this is command injection rather than exposed perception, but I do not mark perception_feeds_action because the consequence is direct actuation, not a perception/world-model feed (per definition, dosing command falsification is actuation control). Crosses RF/protocol -> device -> physical/safety boundaries -> boundary_crossing true, CH:3. Protocol weakness is shared across an entire product family (same unauthenticated proprietary RF), reusable knowledge -> SR:4. Not remotely scalable; per-patient proximity required -> SX:2. No software patch possible for legacy pumps; recall and hardware replacement / migration to newer models -> OR:4, recovery_needs_fleet_action true. Report-backed advisory, no in-the-wild exploitation -> EV:2, active_exploitation false.

DATA_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:2/EC:2/EX:2/PH:4/DP:3/AT:2/CH:2/SR:4/SX:2/OR:4/EV:2/LS:MITIGATED

Exposure EX=2 (reachability and complexity-bound) · bands PH=CRITICAL · DP=HIGH · AT=ELEVATED → base CRITICAL · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.

Same adjacent-RF position and proprietary-protocol skill requirement -> RE:2, EC:2. Confidentiality rated Low (C:L): attacker can intercept and read patient/device RF data including health/device operational state -> DP:3 (health + sensitive device/dosing state). Reading-only consequence here gives bounded session/component exposure of patient data, not config/firmware control -> AT:2. No physical/safety effect on the pure-read path -> PH:0. Crosses RF -> device/app data boundary -> boundary_crossing true, CH:2. Same family-wide unauthenticated protocol enables reuse of interception technique -> SR:4. Per-patient proximity, not remotely scalable -> SX:2. No patch; legacy hardware replacement -> OR:4, recovery_needs_fleet_action true. Report-backed -> EV:2, not exploited in wild -> active_exploitation false.

Published baseline

  • v3.1 7.1 HIGH — CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:H — CISA/ICS-CERT via NVD
  • v3.0 8.8 HIGH — CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H — NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0036 (“Medtronic MiniMed 508 / Paradigm insulin pumps - unauthenticated RF allows insulin delivery control”), paths.cfse.ai/CPATH-2026-0036 (published 2026-06-03).