CPATH-2026-0039 · Medical IoT

Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI

Two or more co-dominant consequence paths connect the public security record to a provisional HIGH consequence band.

Candidate bandHIGH
Co-dominant pathsAccount authority + Data privacy

These paths are co-dominant because each reaches the record's highest candidate band, HIGH; no array-order tie-break is applied.

Causal model

What has to happen for this consequence to hold?

2 candidate paths · explicit source, inference, and assumption boundaries.

Authority · Co-dominant path

Account authority

The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.

HIGH
  1. accessSource-backed

    Per-device physical access

    The attacker needs physical possession of an unwiped, lost, decommissioned, or resold Wireless Battery Module.

    EvidenceNVD

  2. boundaryModel inference

    Cross-domain authority chain

    A secret recovered from one discarded module can bridge into the hospital network and other reachable systems.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Bounded function authority

    The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Account authority

    The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Coordinated operational recovery

    Recovery may require hospital-wide credential rotation plus reliable wiping and decommissioning controls for every module.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 1
Per-device physical access

The attacker needs physical possession of an unwiped, lost, decommissioned, or resold Wireless Battery Module.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Once the module is in hand, the cleartext wireless credential can be extracted through a straightforward local inspection.

Source-backedNVD
ExposureEX 1
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 2
Operational safety effect

The credential opens a hospital network position but does not directly alter pump therapy.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The module stores hospital Wi-Fi credentials alongside protected health and operational data.

Model inference
AuthorityAT 2
Bounded function authority

The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.

Model inference
Scale and recovery
ChainabilityCH 4
Cross-domain authority chain

A secret recovered from one discarded module can bridge into the hospital network and other reachable systems.

Model inference
Reuse scaleSR 4
Shared fleet-wide primitive

A recovered network credential may be shared across a deployment and useful beyond the single module that exposed it.

Operational assumption
Execution scaleSX 3
Deployment-wide with setup

One recovered credential can apply across its wireless deployment, although the initial extraction still requires one physical module.

Operational assumption
Recovery burdenOR 3
Coordinated operational recovery

Recovery may require hospital-wide credential rotation plus reliable wiping and decommissioning controls for every module.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. The recovered password grants bounded access to the hospital wireless network, not pump administration or firmware control.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:1/EC:4/EX:1/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Privacy · Co-dominant path

Data privacy

The module contains protected health information and treatment-related data at rest.

HIGH
  1. accessSource-backed

    Per-device physical access

    The attacker must physically obtain an unwiped Wireless Battery Module.

    EvidenceNVD

  2. boundaryModel inference

    One cross-boundary bridge

    The exposure crosses from a discarded device into patient data, but the record itself is not an authority credential.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  3. capabilityModel inference

    Sensitive device or personal data

    The module contains protected health information and treatment-related data at rest.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  4. consequenceModel inference

    Data privacy

    The module contains protected health information and treatment-related data at rest.

    EvidenceNo direct citation — inspect the declared inference or assumption.

  5. recoveryOperational assumption

    Patch, reset, or reconfiguration

    Mitigation combines software and process changes with verified wiping before loss, return, resale, or decommissioning.

    EvidenceNo direct citation — inspect the declared inference or assumption.

Decision rationale

Why this band?

The compact score is separated into the facts and judgments that produced it.

Reach and effort
ReachabilityRE 1
Per-device physical access

The attacker must physically obtain an unwiped Wireless Battery Module.

Source-backedNVD
Execution complexityEC 4
Straightforward operation

Protected health information is stored in cleartext and can be read directly once the module is accessed.

Source-backedNVD
ExposureEX 1
Access position limits exposure

The technique is easier to perform than it is to position against a target, so access is the constraining factor.

Model inference
Consequence
Physical / safetyPH 0
No direct physical effect

Reading the stored record does not itself change infusion therapy.

Model inference
Data / perceptionDP 3
Sensitive device or personal data

The module contains protected health information and treatment-related data at rest.

Model inference
AuthorityAT 1
Read-only or preparatory access

This path is read-only disclosure and does not grant pump configuration or firmware authority.

Model inference
Scale and recovery
ChainabilityCH 2
One cross-boundary bridge

The exposure crosses from a discarded device into patient data, but the record itself is not an authority credential.

Model inference
Reuse scaleSR 2
Repeatable method

The inspection method is repeatable, while each module contains its own patient and device records.

Operational assumption
Execution scaleSX 1
One device at a time

Every disclosure requires physical access to a separate unwiped module.

Operational assumption
Recovery burdenOR 2
Patch, reset, or reconfiguration

Mitigation combines software and process changes with verified wiping before loss, return, resale, or decommissioning.

Operational assumption
Confidence and status
Evidence strengthEV 3
Reproduced or strongly report-backed

NVD supports a reproduced or strongly report-backed condition; this registry still keeps consequence review separate from exploit confirmation.

Source-backedNVD
LivenessLS Patch available
A patch is available

A vendor fix is available, while deployment and upgrade completion remain separate operational questions.

Source-backedNVD

Decision trail

How the final band follows

  1. Base bandHIGH
  2. No adjustment

    The HIGH base band remains final because no separate cap or systemic uplift applies. The module contains protected health information and treatment-related data at rest.

  3. Final candidate bandHIGH
Technical vector
Compact machine notationCPATH:1.0-candidate/TT:DATA_PRIVACY/RE:1/EC:4/EX:1/PH:0/DP:3/AT:1/CH:2/SR:2/SX:1/OR:2/EV:3/LS:PATCH_AVAILABLERead the scoring method →

Triage implication

Verify the authority transition before acting on the band.

Prioritize the trust boundary the path crosses, then verify which privileged identities, services, or firmware controls become reachable.

Evidence ledger

Public sources used by this record.

Every named source includes a public link. Path review remains separate from citation coverage.

Published baseline

Keep exploit severity and consequence reasoning distinct.

RelationshipPaths model is higher
Baseline confidencehigh
Scored2026-06-03
v3.1 · 4.2 MEDIUMBaxter/Product Security via NVD / NVD
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Original scorer notes

The source narrative behind the structured explanation.

Retained for provenance and historical review, not as the recommended way to understand the assessment.

Read the original scorer notes

Assessment

CFSE Consequence Paths assesses Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI at HIGH — the worst of 2 risk paths (authority and privacy). The dominant consequence is not immediate pump control; it is that one unwiped WBM can expose reusable hospital Wi-Fi credentials, turning a physical data-extraction issue into a network-access and credential-rotation problem.

Vulnerability

CVE-2022-26390 covers cleartext storage of network credentials and, for Spectrum IQ deployments using auto programming, PHI on the Wireless Battery Module (WBM). The attacker needs physical possession of a device that has not had data and settings erased. Related Baxter WBM findings, such as the format-string and unauthenticated reconfiguration CVEs, are not scored in this entry.

Where Paths differs from CVSS

CVSS scores the declared CVE narrowly: physical access, high attack complexity, confidentiality impact, no integrity or availability impact. That produces 4.2 Medium.

The Paths model agrees that the direct data-read path is local and bounded. The disagreement is about what the extracted data is. If the WBM contains a still-valid organization Wi-Fi credential, the harm is not only “someone read data from one discarded battery.” It can become a portable credential for hospital network access, with recovery requiring shared wireless credential rotation across the affected environment. That reusable-authority consequence is not represented by the CVSS C:H/I:N/A:N vector.

This entry should be read with that condition explicit: the Paths uplift depends on shared or reusable Wi-Fi credentials remaining valid. If a deployment uses per-device credentials, short credential lifetime, and confirmed wipe before decommissioning, the ACCOUNT_AUTHORITY path should be reduced.

CFSE Consequence Paths analysis

The vulnerability is decomposed into one risk path per terminal consequence. Each path is scored on its exposure (reachability × execution complexity) and the authority, perception, and physical/safety it reaches, together with its scale of reuse, scale of execution, and recoverability.

ACCOUNT_AUTHORITYHIGH

CPATH:1.0-candidate/TT:ACCOUNT_AUTHORITY/RE:1/EC:4/EX:1/PH:2/DP:3/AT:2/CH:4/SR:4/SX:3/OR:3/EV:3/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=ELEVATED · DP=HIGH · AT=ELEVATED → base HIGH · caps low-exposure cap → assessed HIGH.

The terminal consequence is the stored Wi-Fi credential. RE:1 because the attacker needs physical possession of an unwiped WBM. EC:4 because, once the issue is known and the device is in hand, extracting the cleartext credential is straightforward. AT:2 because the credential grants bounded hospital wireless-network access, not pump admin or firmware authority. DP:3 because credentials and PHI are sensitive operational/health data. CH:4 because a device-local secret can become a bridge into the hospital network. SR:4/SX:3 apply when the credential is shared or reusable across a deployment: one recovered/resold device can expose access useful beyond that one unit. OR:3 because recovery may require network-wide credential rotation plus decommissioning hygiene, not just patching a single pump. EV:3 because Rapid7 reproduced the issue on hardware.

DATA_PRIVACYHIGH

CPATH:1.0-candidate/TT:DATA_PRIVACY/RE:1/EC:4/EX:1/PH:0/DP:3/AT:1/CH:2/SR:2/SX:1/OR:2/EV:3/LS:PATCH_AVAILABLE

Exposure EX=1 (reachability-bound) · bands PH=MONITOR · DP=HIGH · AT=ELEVATED → base HIGH · caps low-exposure cap, privacy-only cap → assessed HIGH.

This is the part CVSS mostly captures. RE:1 requires physical possession of an unwiped, lost, decommissioned, or resold device. EC:4 once the device is in hand. DP:3 because PHI is health-sensitive data at rest. AT:1 because this path is read-only exposure, not configuration or firmware authority. PH:0 because the PHI read does not itself create a safety effect. CH:2 because it crosses a device-to-data boundary but the PHI itself is not a reusable authority bridge. SR:2/SX:1 because PHI is largely per-device/per-patient rather than fleet-portable. OR:2 because mitigation is wipe-before-decommission guidance plus software/process remediation. EV:3 because Rapid7 reproduced the issue on hardware.

Published baseline

  • v3.1 4.2 MEDIUM — CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N — Baxter/Product Security via NVD / NVD

The published baseline above is retained for source review. The registry records the reachable consequence path, including deployment-specific cyber-physical consequence, physical/safety impact, scale, and recovery burden.

Sources

Related paths

Compare the boundary, not only the product.

Cite this entryCFSE Consequence Paths Registry 1.0-candidate, CPATH-2026-0039 (“Baxter Sigma Spectrum WBM - cleartext Wi-Fi credentials and PHI”), paths.cfse.ai/CPATH-2026-0039 (published 2026-06-03).