Causal model
What has to happen for this consequence to hold?
2 candidate paths · explicit source, inference, and assumption boundaries.
Authority · Co-dominant path
Account authority
The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.
Per-device physical access
The attacker needs physical possession of an unwiped, lost, decommissioned, or resold Wireless Battery Module.
EvidenceNVD
Cross-domain authority chain
A secret recovered from one discarded module can bridge into the hospital network and other reachable systems.
EvidenceNo direct citation — inspect the declared inference or assumption.
Bounded function authority
The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Account authority
The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.
EvidenceNo direct citation — inspect the declared inference or assumption.
Coordinated operational recovery
Recovery may require hospital-wide credential rotation plus reliable wiping and decommissioning controls for every module.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 1 - Per-device physical access
The attacker needs physical possession of an unwiped, lost, decommissioned, or resold Wireless Battery Module.
- Execution complexity
EC 4 - Straightforward operation
Once the module is in hand, the cleartext wireless credential can be extracted through a straightforward local inspection.
- Exposure
EX 1 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 2 - Operational safety effect
The credential opens a hospital network position but does not directly alter pump therapy.
- Data / perception
DP 3 - Sensitive device or personal data
The module stores hospital Wi-Fi credentials alongside protected health and operational data.
- Authority
AT 2 - Bounded function authority
The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.
Scale and recovery
- Chainability
CH 4 - Cross-domain authority chain
A secret recovered from one discarded module can bridge into the hospital network and other reachable systems.
- Reuse scale
SR 4 - Shared fleet-wide primitive
A recovered network credential may be shared across a deployment and useful beyond the single module that exposed it.
- Execution scale
SX 3 - Deployment-wide with setup
One recovered credential can apply across its wireless deployment, although the initial extraction still requires one physical module.
- Recovery burden
OR 3 - Coordinated operational recovery
Recovery may require hospital-wide credential rotation plus reliable wiping and decommissioning controls for every module.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:1/EC:4/EX:1/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →Privacy · Co-dominant path
Data privacy
The module contains protected health information and treatment-related data at rest.
Per-device physical access
The attacker must physically obtain an unwiped Wireless Battery Module.
EvidenceNVD
One cross-boundary bridge
The exposure crosses from a discarded device into patient data, but the record itself is not an authority credential.
EvidenceNo direct citation — inspect the declared inference or assumption.
Sensitive device or personal data
The module contains protected health information and treatment-related data at rest.
EvidenceNo direct citation — inspect the declared inference or assumption.
Data privacy
The module contains protected health information and treatment-related data at rest.
EvidenceNo direct citation — inspect the declared inference or assumption.
Patch, reset, or reconfiguration
Mitigation combines software and process changes with verified wiping before loss, return, resale, or decommissioning.
EvidenceNo direct citation — inspect the declared inference or assumption.
Decision rationale
Why this band?
The compact score is separated into the facts and judgments that produced it.
Reach and effort
- Reachability
RE 1 - Per-device physical access
The attacker must physically obtain an unwiped Wireless Battery Module.
- Execution complexity
EC 4 - Straightforward operation
Protected health information is stored in cleartext and can be read directly once the module is accessed.
- Exposure
EX 1 - Access position limits exposure
The technique is easier to perform than it is to position against a target, so access is the constraining factor.
Consequence
- Physical / safety
PH 0 - No direct physical effect
Reading the stored record does not itself change infusion therapy.
- Data / perception
DP 3 - Sensitive device or personal data
The module contains protected health information and treatment-related data at rest.
- Authority
AT 1 - Read-only or preparatory access
This path is read-only disclosure and does not grant pump configuration or firmware authority.
Scale and recovery
- Chainability
CH 2 - One cross-boundary bridge
The exposure crosses from a discarded device into patient data, but the record itself is not an authority credential.
- Reuse scale
SR 2 - Repeatable method
The inspection method is repeatable, while each module contains its own patient and device records.
- Execution scale
SX 1 - One device at a time
Every disclosure requires physical access to a separate unwiped module.
- Recovery burden
OR 2 - Patch, reset, or reconfiguration
Mitigation combines software and process changes with verified wiping before loss, return, resale, or decommissioning.
Confidence and status
- Evidence strength
EV 3 - Reproduced or strongly report-backed
NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.
- Liveness
LS Patch available - A patch is available
A vendor fix is available, while deployment and upgrade completion remain separate operational questions.
Decision trail
How the final band follows
- Base bandHIGH
- No adjustment
The HIGH base band remains final because no separate cap or systemic uplift applies. The module contains protected health information and treatment-related data at rest.
- Final candidate bandHIGH
Technical vector
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:1/EC:4/EX:1/PH:0/DP:3/AT:1/CH:2/SR:2/SX:1/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →Triage implication
Verify the authority transition before acting on the band.
Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.
Evidence ledger
Public sources used by this record.
Every named source includes a public link. Path review remains separate from citation coverage.
- advisoryNVD
NVD
- otherRapid7 disclosure
Rapid7 disclosure
Published baseline
Keep exploit severity and consequence reasoning distinct.
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NCVE recordsCVE-2022-26390
Original scorer notes
The source narrative behind the structured explanation.
Retained for provenance and historical review, not as the recommended way to understand the assessment.
Read the original scorer notes
Assessment
CFSE Consequence Paths assesses Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI at HIGH — the worst of 2 risk paths (authority and privacy). The dominant consequence is not immediate pump control; it is that one unwiped WBM can expose reusable hospital Wi-Fi credentials, turning a physical data-extraction issue into a network-access and credential-rotation problem.
Vulnerability
CVE-2022-26390 covers cleartext storage of network credentials and, for Spectrum IQ deployments using auto programming, PHI on the Wireless Battery Module (WBM). The attacker needs physical possession of a device that has not had data and settings erased. Related Baxter WBM findings, such as the format-string and unauthenticated reconfiguration CVEs, are not scored in this entry.
Where Paths differs from CVSS
CVSS scores the declared CVE narrowly: physical access, high attack complexity, confidentiality impact, no integrity or availability impact. That produces 4.2 Medium.
The Paths model agrees that the direct data-read path is local and bounded. The disagreement is about what the extracted data is. If the WBM contains a still-valid organization Wi-Fi credential, the harm is not only “someone read data from one discarded battery.” It can become a portable credential for hospital network access, with recovery requiring shared wireless credential rotation across the affected environment. That reusable-authority consequence is not represented by the CVSS C:H/I:N/A:N vector.
This entry should be read with that condition explicit: the Paths uplift depends on shared or reusable Wi-Fi credentials remaining valid. If a deployment uses per-device credentials, short credential lifetime, and confirmed wipe before decommissioning, the ACCOUNT_AUTHORITY path should be reduced.
CFSE Consequence Paths analysis
The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.
ACCOUNT_AUTHORITY → HIGH
CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:1/EC:4/EX:1/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=ELEVATED · DP=HIGH · AT=ELEVATED → base HIGH · caps low-exposure cap → assessed HIGH.
The terminal consequence is the stored Wi-Fi credential. RE:1 because the attacker needs physical possession of an unwiped WBM. EC:4 because, once the issue is known and the device is in hand, extracting the cleartext credential is straightforward. AT:2 because the credential grants bounded hospital wireless-network access, not pump admin or firmware authority. DP:3 because credentials and PHI are sensitive operational/health data. CH:4 because a device-local secret can become a bridge into the hospital network. SR:4/SX:3 apply when the credential is shared or reusable across a deployment: one recovered/resold device can expose access useful beyond that one unit. OR:3 because recovery may require network-wide credential rotation plus decommissioning hygiene, not just patching a single pump. EV:3 because Rapid7 reproduced the issue on hardware.
DATA_PRIVACY → HIGH
CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:1/EC:4/EX:1/PH:0/DP:3/AT:1/CH:2/SR:2/SX:1/OR:2/EV:3/LS:PATCH_AVAILABLE
Exposure EX=1 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps low-exposure cap, privacy-only cap → assessed HIGH.
This is the part CVSS mostly captures. RE:1 requires physical possession of an unwiped, lost, decommissioned, or resold device. EC:4 once the device is in hand. DP:3 because PHI is health-sensitive data at rest. AT:1 because this path is read-only exposure, not configuration or firmware authority. PH:0 because the PHI read does not itself create a safety effect. CH:2 because it crosses a device-to-data boundary but the PHI itself is not a reusable authority bridge. SR:2/SX:1 because PHI is largely per-device/per-patient rather than fleet-portable. OR:2 because mitigation is wipe-before-decommission guidance plus software/process remediation. EV:3 because Rapid7 reproduced the issue on hardware.
Published baseline
- v3.1 4.2 MEDIUM —
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N— Baxter/Product Security via NVD / NVD
The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.
Sources
CFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0039 (“Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI”), paths.cfse.ai/CPATH-2026-0039 (published 2026-06-03).