Causal model
What has to happen for this consequence to hold?
3 candidate paths · explicit source, inference, and assumption boundaries.
Perception · Co-dominant path
Perception-to-action
Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.
Network-reachable without prior access
The same exposed SSH private key authenticates to reachable CARESCAPE and ApexPro monitoring systems without a per-device password.
EvidenceNVD
Cross-domain authority chain
The shared key crosses from the network into monitor administration and then into the clinical decisions driven by alarms and displays.
EvidenceNo direct citation — inspect the declared inference or assumption.
Safety-driving perception or intimate data
Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Perception-to-action
Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Recovery requires firmware that rotates the key, network isolation, and verification across every affected monitoring system.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
The same exposed SSH private key authenticates to reachable CARESCAPE and ApexPro monitoring systems without a per-device password.
- Execution complexity
EC 4 - Straightforward operation
Using the recovered key to open an SSH session is a straightforward standard client operation.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
Changed alarm thresholds or patient displays can cause missed or inappropriate clinical response and create a severe safety consequence.
- Data / perception
DP 4 - Safety-driving perception or intimate data
Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.
- Authority
AT 3 - Administrative or command authority
SSH grants administrator-level control of monitoring components, but not a GE firmware-signing root.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
The shared key crosses from the network into monitor administration and then into the clinical decisions driven by alarms and displays.
- Reuse scale
SR 4 - Shared fleet-wide primitive
One exposed private key authenticates across the affected product line, making the credential directly reusable.
- Execution scale
SX 4 - Remote fleet-scale execution
The shared key can open sessions on many reachable monitors without obtaining a separate credential for each unit.
- Recovery burden
OR 4 - Fleet action or replacement
Recovery requires firmware that rotates the key, network isolation, and verification across every affected monitoring system.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. Interactive access can falsify the patient-monitoring and alarm state that clinicians use for treatment decisions.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:4/DP:4/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Safety · Co-dominant path
Device-control safety
The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.
Network-reachable without prior access
Any attacker who can reach SSH on an affected monitor can present the exposed shared private key.
EvidenceNVD
Cross-domain authority chain
Network access crosses into monitor administration and then into the safety functions that alert clinical staff.
EvidenceNo direct citation — inspect the declared inference or assumption.
Severe therapy or actuation consequence
The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.
EvidenceNo direct citation — inspect the declared inference or assumption.
Device-control safety
The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
The fleet needs key-rotating firmware, segmentation, and confirmation that the old key no longer authenticates.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
Any attacker who can reach SSH on an affected monitor can present the exposed shared private key.
- Execution complexity
EC 4 - Straightforward operation
A standard SSH client and the known key are sufficient to obtain interactive administrator access.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 4 - Severe therapy or actuation consequence
The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.
- Data / perception
DP 3 - Sensitive device or personal data
Administrator access includes alarm configuration, device state, and clinical monitoring data.
- Authority
AT 3 - Administrative or command authority
The session grants administrator control of monitor configuration and alarms, but not a vendor signing key.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
Network access crosses into monitor administration and then into the safety functions that alert clinical staff.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same universal private key works across affected monitors rather than being unique to one device.
- Execution scale
SX 4 - Remote fleet-scale execution
Reachable systems can be accessed at fleet scale with the same credential and no physical visit.
- Recovery burden
OR 4 - Fleet action or replacement
The fleet needs key-rotating firmware, segmentation, and confirmation that the old key no longer authenticates.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- No adjustment
The EMERGENCY base band remains final because no separate cap or systemic uplift applies. The attacker can silence alarms or make monitors unavailable, directly undermining life-critical patient surveillance.
- Final candidate bandEMERGENCY
Technical vector
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Privacy · Supporting path
Data privacy
The administrator session exposes protected health information, patient monitoring data, and sensitive device state.
Network-reachable without prior access
A reachable monitor accepts the exposed shared SSH key without a device-specific credential.
EvidenceNVD
Reusable multi-stage bridge
The shared credential crosses the network and device boundary into clinical data stored or processed by the monitor.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
The administrator session exposes protected health information, patient monitoring data, and sensitive device state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
The administrator session exposes protected health information, patient monitoring data, and sensitive device state.
EvidenceNo direct citation — inspect the declared inference or assumption.
Fleet action or replacement
Key rotation, fixed firmware, network isolation, and review of exposed clinical data are required across the deployment.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 4 - Network-reachable without prior access
A reachable monitor accepts the exposed shared SSH key without a device-specific credential.
- Execution complexity
EC 4 - Straightforward operation
Opening the administrator session and reading stored or live data uses ordinary SSH and file-access tools.
- Exposure
EX 4 - Reach and effort support the same exposure
The documented reach and required effort are equally permissive, so neither reduces the other.
Consequence
- Physical / safety
PH 1 - Minor physical effect
Reading clinical data is a privacy harm; direct alarm or display manipulation is assessed in the safety paths.
- Data / perception
DP 3 - Sensitive device or personal data
The administrator session exposes protected health information, patient monitoring data, and sensitive device state.
- Authority
AT 2 - Bounded function authority
This path uses the session for data access; broader monitor administration is assessed separately.
Scale and recovery
- Chainability
CH 3 - Reusable multi-stage bridge
The shared credential crosses the network and device boundary into clinical data stored or processed by the monitor.
- Reuse scale
SR 4 - Shared fleet-wide primitive
The same private key can be reused across affected devices and hospital deployments.
- Execution scale
SX 4 - Remote fleet-scale execution
One key supports remote data access to many reachable monitors without per-device credential collection.
- Recovery burden
OR 4 - Fleet action or replacement
Key rotation, fixed firmware, network isolation, and review of exposed clinical data are required across the deployment.
Confidence and status
- Evidence strength
EV 2 - Public report, not reproduced here
NVD reports the condition, but this registry has not independently reproduced this path.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandEMERGENCY
- Evidence-gated cap
The EMERGENCY base consequence is capped at CRITICAL because this path exposes protected health and monitoring data but does not independently reach the separate alarm-manipulation or safety consequence.
- Final candidate bandCRITICAL
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:1/DP:3/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the perception transition before acting on the band.
Validate the deployment-specific transition from digital control or perception to physical action before setting remediation urgency.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HCVE recordsCVE-2020-6961
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key at EMERGENCY — the worst of 3 risk paths (perception, safety). The dominant consequence is manipulated perception that drives action.
Vulnerability
GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
PERCEPTION_TO_ACTION → EMERGENCY
CPATH:1.0-candidate/TT:PERCEPTION_TO_ACTION/RE:4/EC:4/EX:4/PH:4/DP:4/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=EMERGENCY · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
Shared hard-coded SSH key (SR:4) reachable network-wide unauthenticated (RE:4) with trivial connect (EC:4). Once in via SSH the attacker alters monitoring/diagnostic data and alarm thresholds, falsifying the perceived patient state that clinicians act on for life-critical decisions (DP:4 safety-sensor/monitoring state, perception_feeds_action=true, PH:4 credible injury via missed/false alerts). AT:3 = remote interactive software control of monitoring components, not a signing/OTA root. CH:4 cross-domain (network->device->clinical action). SX:4 fleet-scale because identical key reuses across the product line on reachable networks. OR:4 recovery needs firmware that rotates credentials plus fleet network isolation. EV:2 report-backed (CyberMDX/ICS-CERT), no in-the-wild use.
DEVICE_CONTROL_SAFETY → EMERGENCY
CPATH:1.0-candidate/TT:DEVICE_CONTROL_SAFETY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:3/CH:4/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift fleet-reachable authority, recall-class recovery → assessed EMERGENCY.
Same universal SSH key (SR:4, RE:4, EC:4) yields full software-level control: silence/disable alarms and render monitors unusable (A:H). Direct safety actuation on life-critical monitoring -> PH:4. AT:3 admin/service-level interactive control over device config/alarm settings (not a root-of-trust/signing key, so not AT:4). DP:3 sensitive operational/firmware-adjacent state touched. CH:4 boundary_crossing across network/device/safety. SX:4 fleet-scalable via shared key; OR:4 requires credential-rotating firmware plus segmentation across the fleet. EV:2 report-backed.
DATA_PRIVACY → CRITICAL
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:4/EC:4/EX:4/PH:4/DP:3/AT:2/CH:3/SR:4/SX:4/OR:4/EV:2/LS:PATCH_AVAILABLE
Exposure EX=4 (reachability and complexity-bound) · bands PH=EMERGENCY · DP=CRITICAL · AT=CRITICAL → base EMERGENCY · uplift recall-class recovery · caps privacy-only cap → assessed CRITICAL.
SSH access via the shared key (SR:4, RE:4, EC:4) exposes PHI (C:H) -> DP:3 health/PHI data. AT:2 bounded data read via the obtained session. PH:1 privacy harm only, no direct safety. CH:3 chains network access to data exfiltration across boundaries. SX:4 fleet-scale because the same key works against many devices/hospitals without per-device access. OR:4 full recovery requires key rotation via firmware plus isolation across the deployed fleet. EV:2 report-backed disclosure, no confirmed in-the-wild exploitation.
Published baseline
- v3.1 10 CRITICAL —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H— NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0038 (“GE CARESCAPE / ApexPro patient monitoring (MDhex) - exposed shared SSH private key”), paths.cfse.ai/CPATH-2026-0038 (published 2026-06-03).