CPATH-2026-0037 · Medical IoT

Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation

A dominant device-control safety path connects the public security record to a provisional CRITICAL consequence band.

Candidate bandCRITICAL
Dominant pathDevice-control safety

This path is explicitly dominant because it reaches the record's highest candidate band, CRITICAL.

Causal model

What has to happen for this consequence to hold?

1 candidate path · explicit source, inference, and assumption boundaries.

Safety · Dominant path

Device-control safety

Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.

CRITICAL
  1. accessSource-backed

    Proximity or local access

    The attacker must be within radio range during the brief component-pairing event.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The pairing flaw creates one radio-to-command transition into insulin delivery; it does not establish a wider control-plane bridge.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Recovery is per-device and procedural: end the suspect pairing, verify the pump, and apply the available mitigation guidance.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 2
Proximity or local access

The attacker must be within radio range during the brief component-pairing event.

Source-backedNVD
Execution complexityEC 1
Narrow or timing-dependent technique

The technique requires precise timing, specialist equipment, and protocol expertise to impersonate a component during pairing.

Source-backedNVD
ExposureEX 1
Execution effort limits exposure

The interface is broadly reachable, but the required technique keeps practical exposure below that reach.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.

Model inference
Data / perceptionDP 0
No data consequence

The path changes dosing and command state rather than extracting patient records.

Model inference
AuthorityAT 3
Administrative or command authority

A forged paired component can issue insulin-delivery commands, but it does not obtain pump firmware or signing authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The pairing flaw creates one radio-to-command transition into insulin delivery; it does not establish a wider control-plane bridge.

Model inference
Reuse scaleSR 1
Target-specific technique

The attacker must win a new pairing window for each target rather than reuse a shared credential.

Operational assumption
Execution scaleSX 1
One device at a time

Every attempt is one patient and one pairing event at a time within radio range.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Recovery is per-device and procedural: end the suspect pairing, verify the pump, and apply the available mitigation guidance.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Partially mitigated
Partial mitigation leaves residual exposure

Mitigation reduces the path, but rollout coverage or remaining exposed devices is not independently verified by this registry.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandCRITICAL
  2. No adjustment

    The CRITICAL base band remains final because no separate cap or systemic uplift applies. Injected delivery commands can stop insulin or trigger an unintended bolus, causing severe hypoglycemia, hyperglycemia, or ketoacidosis.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:4/DP:0/AT:3/CH:2/SR:1/SX:1/OR:2/EV:2/LS:PARTIALLY_MITIGATEDRead the scoring method →

Triage implication

Verify the safety transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 4.8 MEDIUMsecurity via NVD / NVD
CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation at CRITICAL — the worst of 1 risk path (safety). The dominant consequence is influence over a safety-relevant actuation.

Vulnerability

Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

DEVICE_CONTROL_SAFETYCRITICAL

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:2/EC:1/EX:1/PH:4/DP:0/AT:3/CH:2/SR:1/SX:1/OR:2/EV:2/LS:PARTIALLY_MITIGATED

Exposure EX=1 (execution complexity-bound) · bands PH=CRITICAL · DP=MONITOR · AT=HIGH → base CRITICAL · caps low-exposure cap → assessed CRITICAL.

  • Adjacent RF only (AV:A), attacker must be in wireless proximity during component pairing -> RE:2 (BLE/RF/local-net/proximity). Execution requires high skill, specialized equipment, proximity, and catching the specific pairing event (AC:H, fragile/timing-dependent) -> EC:1. By impersonating a trusted paired component the attacker injects/modifies delivery commands (service/command authority over the pump, but not root-of-trust or firmware/signing) -> AT:3. Credible injury: stopping/slowing insulin (hyperglycemia/DKA) or unintended bolus (hypoglycemia) -> PH:4. CVSS C:N, integrity-only; no confidentiality/perception as scored impact -> DP:0, perception_feeds_action false. Crosses RF/device/physical->safety boundary -> boundary_crossing true, CH:2 (single device-control hop, no reusable cross-domain authority bridge). No portable shared key/credential demonstrated; per-pairing window per device -> SR:1. Per-patient proximity, one-at-a-time, not remotely scalable -> SX:1. Mitigations are largely procedural and do not eliminate the RF design weakness; manipulation may be hard for patient to attribute, but recovery is per-device/procedural not fleet reprovision -> OR:2, recovery_needs_fleet_action false. Report/vendor/researcher-confirmed, no in-the-wild use -> EV:2, LS PARTIALLY_MITIGATED.
  • active_exploitation — false.

Published baseline

  • v3.1 4.8 MEDIUM — CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N — security via NVD / NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0037 (“Medtronic MiniMed / NGP 600 series insulin pumps - RF pairing protocol allows bolus/delivery manipulation”), paths.cfse.ai/CPATH-2026-0037 (published 2026-06-03).