CPATH-2026-0038 · Medical IoT

GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key

Two or more co-dominant consequence paths connect the public security record to a provisional EMERGENCY consequence band.

Candidate bandEMERGENCY
Co-dominant pathsPerception-to-action + Device-control safety

These paths are co-dominant because each reaches the record's highest candidate band, EMERGENCY; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

3 candidate paths · explicit source, inference, and assumption boundaries.

Perception · Co-dominant path

Perception-to-action

Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    The same exposed SSH private key authenticates to reachable CARESCAPE and ApexPro monitoring systems without a per-device password.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    The shared key crosses from the network into monitor administration and then into the clinical decisions driven by alarms and displays.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Safety-driving perception or intimate data

    Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Perception-to-action

    Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Recovery requires firmware that rotates the key, network isolation, and verification across every affected monitoring system.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

The same exposed SSH private key authenticates to reachable CARESCAPE and ApexPro monitoring systems without a per-device password.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Using the recovered key to open an SSH session is a straightforward standard client operation.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

Changed alarm thresholds or patient displays can cause missed or inappropriate clinical response and create a severe safety consequence.

Model inference
Data / perceptionDP 4
Safety-driving perception or intimate data

Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.

Model inference
AuthorityAT 3
Administrative or command authority

SSH grants administrator-level control of monitoring components, but not a GE firmware-signing root.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

The shared key crosses from the network into monitor administration and then into the clinical decisions driven by alarms and displays.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

One exposed private key authenticates across the affected product line, making the credential directly reusable.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

The shared key can open sessions on many reachable monitors without obtaining a separate credential for each unit.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Recovery requires firmware that rotates the key, network isolation, and verification across every affected monitoring system.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:4/DP:4/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Safety · Co-dominant path

Device-control safety

The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.

EMERGENCY
  1. accessSource-backed

    Network-reachable without prior access

    Any attacker who can reach SSH on an affected monitor can present the exposed shared private key.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    Network access crosses into monitor administration and then into the safety functions that alert clinical staff.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Severe therapy or actuation consequence

    The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Device-control safety

    The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    The fleet needs key-rotating firmware, segmentation, and confirmation that the old key no longer authenticates.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

Any attacker who can reach SSH on an affected monitor can present the exposed shared private key.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

A standard SSH client and the known key are sufficient to obtain interactive administrator access.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 4
Severe therapy or actuation consequence

The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

Administrator access includes alarm configuration, device state, and clinical monitoring data.

Model inference
AuthorityAT 3
Administrative or command authority

The session grants administrator control of monitor configuration and alarms, but not a vendor signing key.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

Network access crosses into monitor administration and then into the safety functions that alert clinical staff.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same universal private key works across affected monitors rather than being unique to one device.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

Reachable systems can be accessed at fleet scale with the same credential and no physical visit.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

The fleet needs key-rotating firmware, segmentation, and confirmation that the old key no longer authenticates.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. No adjustment

    The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.

  3. Final candidate bandEMERGENCY
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Supporting path

Data privacy

The administrator session exposes protected health information, patient monitoring data, and sensitive device state.

CRITICAL
  1. accessSource-backed

    Network-reachable without prior access

    A reachable monitor accepts the exposed shared SSH key without a device-specific credential.

    EvidenceNVD

  2. boundaryModel inference

    Reusable multi-stage bridge

    The shared credential crosses the network and device boundary into clinical data stored or processed by the monitor.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    The administrator session exposes protected health information, patient monitoring data, and sensitive device state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    The administrator session exposes protected health information, patient monitoring data, and sensitive device state.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Fleet action or replacement

    Key rotation, fixed firmware, network isolation, and review of exposed clinical data are required across the deployment.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 4
Network-reachable without prior access

A reachable monitor accepts the exposed shared SSH key without a device-specific credential.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Opening the administrator session and reading stored or live data uses ordinary SSH and file-access tools.

Source-backedNVD
ExposureEX 4
Reach and effort support the same exposure

The documented reach and required effort are equally permissive, so neither reduces the other.

Model inference
Consequence
Physical / safetyPH 1
Minor physical effect

Reading clinical data is a privacy harm; direct alarm or display manipulation is assessed in the safety paths.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The administrator session exposes protected health information, patient monitoring data, and sensitive device state.

Model inference
AuthorityAT 2
Bounded function authority

This path uses the session for data access; broader monitor administration is assessed separately.

Model inference
Scale and recovery
ChainabilityCH 3
Reusable multi-stage bridge

The shared credential crosses the network and device boundary into clinical data stored or processed by the monitor.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

The same private key can be reused across affected devices and hospital deployments.

Operational assumption
Execution scaleSX 4
Remote fleet-scale execution

One key supports remote data access to many reachable monitors without per-device credential collection.

Operational assumption
Recovery burdenOR 4
Fleet action or replacement

Key rotation, fixed firmware, network isolation, and review of exposed clinical data are required across the deployment.

Operational assumption
Confidence and status
Evidence strengthEV 2
Public report, not reproduced here

NVD reports the condition, but this registry has not independently reproduced this path.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandEMERGENCY
  2. Evidence-gated cap

    The EMERGENCY base consequence is capped at CRITICAL because this path exposes protected health and monitoring data but does not independently reach the separate alarm-manipulation or safety consequence.

  3. Final candidate bandCRITICAL
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:1/DP:3/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the perception transition before acting on the band.

Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 10 CRITICALNVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key at EMERGENCY — the worst of 3 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.

Vulnerability

GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

PERCEPTION_TO_ACTIONEMERGENCY

CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:4/DP:4/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=EMERGENCY · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

Shared hard-coded SSH key (SR:4) reachable network-wide unauthenticated (RE:4) with trivial connect (EC:4). Once in via SSH the attacker alters monitoring/diagnostic data and alarm thresholds, falsifying the perceived patient state that clinicians act on for life-critical decisions (DP:4 safety-sensor/monitoring state, perception_feeds_action=true, PH:4 credible injury via missed/false alerts). AT:3 = remote interactive software control of monitoring components, not a signing/OTA root. CH:4 cross-domain (network->device->clinical action). SX:4 fleet-scale because identical key reuses across the product line on reachable networks. OR:4 recovery needs firmware that rotates credentials plus fleet network isolation. EV:2 report-backed (CyberMDX/ICS-CERT), no in-the-wild use.

DEVICE_CONTROL_SAFETYEMERGENCY

CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.

Same universal SSH key (SR:4, RE:4, EC:4) yields full software-level control: silence/disable alarms and render monitors unusable (A:H). Direct safety actuation on life-critical monitoring -> PH:4. AT:3 admin/service-level interactive control over device config/alarm settings (not a root-of-trust/signing key, so not AT:4). DP:3 sensitive operational/firmware-adjacent state touched. CH:4 boundary_crossing across network/device/safety. SX:4 fleet-scalable via shared key; OR:4 requires credential-rotating firmware plus segmentation across the fleet. EV:2 report-backed.

DATA_PRIVACYCRITICAL

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE

Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.

SSH access via the shared key (SR:4, RE:4, EC:4) exposes PHI (C:H) -> DP:3 health/PHI data. AT:2 bounded data read via the obtained session. PH:1 privacy harm only, no direct safety. CH:3 chains network access to data exfiltration across boundaries. SX:4 fleet-scale because the same key works against many devices/hospitals without per-device access. OR:4 full recovery requires key rotation via firmware plus isolation across the deployed fleet. EV:2 report-backed disclosure, no confirmed in-the-wild exploitation.

Published baseline

  • v3.1 10 CRITICAL — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H — NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0038 (“GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key”), paths.cfse.ai/CPATH-2026-0038 (published 2026-06-03).