Causal model
What has to happen for this consequence to hold?
1 candidate path · explicit source, inference, and assumption boundaries.
Safety · Dominant path
Device-control safety
Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.
Proximity or local access
The attacker must be within radio range during the brief component-pairing event.
EvidenceNVD
One cross-boundary bridge
The pairing flaw creates one radio-to-command transition into insulin delivery; it does not establish a wider control-plane bridge.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Recovery is per-device and procedural: end the suspect pairing, verify the pump, and apply the available mitigation guidance.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 2 - Proximity or local access
The attacker must be within radio range during the brief component-pairing event.
- Execution complexity
EC 1 - Narrow or timing-dependent technique
The technique requires precise timing, specialist equipment, and protocol expertise to impersonate a component during pairing.
- Exposure
EX 1 - Execution effort limits exposure
The interface is broadly reachable, but the required technique keeps practical exposure below that reach.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.
- Data / perception
DP 0 - No data consequence
The path changes dosing and command state rather than extracting patient records.
- Authority
AT 3 - Administrative or command authority
A forged paired component can issue insulin-delivery commands, but it does not obtain pump firmware or signing authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The pairing flaw creates one radio-to-command transition into insulin delivery; it does not establish a wider control-plane bridge.
- Reuse scale
SR 1 - Target-specific technique
The attacker must win a new pairing window for each target rather than reuse a shared credential.
- Execution scale
SX 1 - One device at a time
Every attempt is one patient and one pairing event at a time within radio range.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Recovery is per-device and procedural: end the suspect pairing, verify the pump, and apply the available mitigation guidance.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Partially mitigated - Partial mitigation leaves residual exposure
Mitigation reduces the path, but rollout coverage or remaining exposed devices is not independently verified by this registry.
Decision trail
How the final band follows
- Base bandCRITICAL
- No adjustment
The CRITICAL base band remains final because no separate cap or systemic uplift applies. Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:4/DP:0/AT:3/CH:2/SR:1/SX:1/OR:2/EV:2/LS:PARTIALLY_MITIGATEDRead the scoring method →Triage implication
Verify the safety transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:NCVE recordsCVE-2022-32537
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation at CRITICAL — the worst of 1 risk path (safety). The dominant consequence is influence over a safety-relevant actuation.
Vulnerability
Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
DEVICE_CONTROL_SAFETY → CRITICAL
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:4/DP:0/AT:3/CH:2/SR:1/SX:1/OR:2/EV:2/LS:PARTIALLY_MITIGATED
Exposure EX=1 (execution complexity-bound) · bands PH=CRITICAL · DP=MONITOR · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.
- Adjacent RF only (AV:A), attacker must be in wireless proximity during component pairing -> RE:2 (BLE/RF/local-net/proximity). Execution requires high skill, specialized equipment, proximity, and catching the specific pairing event (AC:H, fragile/timing-dependent) -> EC:1. By impersonating a trusted paired component the attacker injects/modifies delivery commands (service/command authority over the pump, but not root-of-trust or firmware/signing) -> AT:3. Credible injury: stopping/slowing insulin (hyperglycemia/DKA) or unintended bolus (hypoglycemia) -> PH:4. CVSS C:N, integrity-only; no confidentiality/perception as scored impact -> DP:0, perception_feeds_action false. Crosses RF/device/physical->safety boundary -> boundary_crossing true, CH:2 (single device-control hop, no reusable cross-domain authority bridge). No portable shared key/credential demonstrated; per-pairing window per device -> SR:1. Per-patient proximity, one-at-a-time, not remotely scalable -> SX:1. Mitigations are largely procedural and do not eliminate the RF design weakness; manipulation may be hard for patient to attribute, but recovery is per-device/procedural not fleet reprovision -> OR:2, recovery_needs_fleet_action false. Report/vendor/researcher-confirmed, no in-the-wild use -> EV:2, LS PARTIALLY_MITIGATED.
- active_exploitation — false.
Published baseline
- v3.1 4.8 MEDIUM —
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N— security via NVD / NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0037 (“Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation”), paths.cfse.ai/CPATH-2026-0037 (published 2026-06-03).