NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Risk workspace
Inherent and residual ratings under RM-5x5 v2.1; a cell filters, a row opens the assessment.
Inherent risk matrix
- Low 1-4
- Medium 5-9
- High 10-16
- Critical 17-25
| Impact | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 0 | 0 | 2 | 1 | 0 |
| 4 | 0 | 1 | 0 | 2 | 0 |
| 3 | 0 | 0 | 3 | 1 | 0 |
| 2 | 0 | 1 | 0 | 0 | 0 |
| 1 | 0 | 0 | 0 | 0 | 0 |
- Attacker sends unauthorized dosing commandRSK-000118TV-000118SafetyCritical
- Score
- L4 × I5 = 20
- Residual
- High10
- Replay of captured dosing command re-doses patientRSK-000124TV-000124High
- Score
- L4 × I4 = 16
- Residual
- Medium8
- Unauthenticated serial service port grants privileged shellRSK-000101TV-000101High
- Score
- L4 × I4 = 16
- Residual
- Low4
- Unsigned application firmware package accepted by update agentRSK-000112TV-000112High
- Score
- L3 × I5 = 15
- Residual
- Not projected
- Tampered drug library uploaded from compromised pharmacy workstationRSK-000129TV-000129SafetyHigh
- Score
- L3 × I5 = 15
- Residual
- Medium5
- Gateway flood starves dosing command channelRSK-000133TV-000133High
- Score
- L4 × I3 = 12
- Residual
- Medium6
- Rogue device impersonates clinician app over BLE pairingRSK-000126TV-000126High
- Score
- L3 × I3 = 9override
- Residual
- Not projected
- Maintenance actor alters or truncates pump audit logRSK-000127TV-000127Medium
- Score
- L3 × I3 = 9
- Residual
- Medium6
- Cloud telemetry stream exposes PHI to unauthorized readerRSK-000131TV-000131Medium
- Score
- L3 × I3 = 9
- Residual
- Low4
- Maintenance mode left enabled exposes diagnostic shellRSK-000135TV-000135Medium
- Score
- L2 × I4 = 8
- Residual
- Not projected
- Protocol downgrade between gateway and cloud ingestionRSK-000138TV-000138Low
- Score
- L2 × I2 = 4
- Residual
- Not projected
11 assessments
Unauthenticated serial service port grants privileged shell
RSK-000101ClosedHigh
Inherent
HighL4 × I4
Residual
LowL1 × I4
Factors (1 to 5)
Exploitability4
Impact: confidentiality3
Impact: integrity4
Impact: availability3
Impact: authenticity3
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 4 | 20% |
| Impact: confidentiality | 3 | 15% |
| Impact: integrity | 4 | 20% |
| Impact: availability | 3 | 15% |
| Impact: authenticity | 3 | 15% |
| Detectability | 3 | 15% |
Safety consequence: NoneScope: Single deviceUncertainty: Low
- Exploitability
- 4/5
- Any bedside actor with a serial cable (pre-mitigation).
- Impact: confidentiality
- 3/5
- Full device data readable via shell.
- Impact: integrity
- 4/5
- Privileged configuration change possible.
- Impact: availability
- 3/5
- Device disable possible.
- Impact: authenticity
- 3/5
- Unattributed privileged actions.
- Safety consequence
- None
- Maintenance interlock prevents infusion during shell access.
- Affected scope
- Single device
- Physical access required per device.
- Detectability
- 3/5
- Console sessions logged after 3.1.4.
- Uncertainty
- Low
- Bench-verified.
Baseline-cycle assessment under method v2.0; retained immutable with the DRB-0007 as-of record (DR-SEC-018).
- Threat
- TV-000101
- Assessor
- Marcus Chen
- Assessed
- 21 Jan 2026, 09:00 UTC
- Method / matrix
- RM-5x5 v2.0 · MTX-2025-02