NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Risk workspace
Inherent and residual ratings under RM-5x5 v2.1; a cell filters, a row opens the assessment.
Inherent risk matrix
- Low 1-4
- Medium 5-9
- High 10-16
- Critical 17-25
| Impact | 1 | 2 | 3 | 4 | 5 |
|---|---|---|---|---|---|
| 5 | 0 | 0 | 2 | 1 | 0 |
| 4 | 0 | 1 | 0 | 2 | 0 |
| 3 | 0 | 0 | 3 | 1 | 0 |
| 2 | 0 | 1 | 0 | 0 | 0 |
| 1 | 0 | 0 | 0 | 0 | 0 |
- Attacker sends unauthorized dosing commandRSK-000118TV-000118SafetyCritical
- Score
- L4 × I5 = 20
- Residual
- High10
- Replay of captured dosing command re-doses patientRSK-000124TV-000124High
- Score
- L4 × I4 = 16
- Residual
- Medium8
- Unauthenticated serial service port grants privileged shellRSK-000101TV-000101High
- Score
- L4 × I4 = 16
- Residual
- Low4
- Unsigned application firmware package accepted by update agentRSK-000112TV-000112High
- Score
- L3 × I5 = 15
- Residual
- Not projected
- Tampered drug library uploaded from compromised pharmacy workstationRSK-000129TV-000129SafetyHigh
- Score
- L3 × I5 = 15
- Residual
- Medium5
- Gateway flood starves dosing command channelRSK-000133TV-000133High
- Score
- L4 × I3 = 12
- Residual
- Medium6
- Rogue device impersonates clinician app over BLE pairingRSK-000126TV-000126High
- Score
- L3 × I3 = 9override
- Residual
- Not projected
- Maintenance actor alters or truncates pump audit logRSK-000127TV-000127Medium
- Score
- L3 × I3 = 9
- Residual
- Medium6
- Cloud telemetry stream exposes PHI to unauthorized readerRSK-000131TV-000131Medium
- Score
- L3 × I3 = 9
- Residual
- Low4
- Maintenance mode left enabled exposes diagnostic shellRSK-000135TV-000135Medium
- Score
- L2 × I4 = 8
- Residual
- Not projected
- Protocol downgrade between gateway and cloud ingestionRSK-000138TV-000138Low
- Score
- L2 × I2 = 4
- Residual
- Not projected
11 assessments
Attacker sends unauthorized dosing command
RSK-000118Mitigation pendingCritical
Inherent
CriticalL4 × I5
Residual
HighL2 × I5
Factors (1 to 5)
Exploitability4
Impact: confidentiality2
Impact: integrity5
Impact: availability5
Impact: authenticity5
Detectability2
| Category | Value | Share |
|---|---|---|
| Exploitability | 4 | 17% |
| Impact: confidentiality | 2 | 9% |
| Impact: integrity | 5 | 22% |
| Impact: availability | 5 | 22% |
| Impact: authenticity | 5 | 22% |
| Detectability | 2 | 9% |
Safety consequence: Potential hazardous situationScope: Multi patientUncertainty: LowSafety-risk linkage: confirmed
- Exploitability
- 4/5
- Reachable from any clinical-network foothold; commodity HTTP tooling suffices; only segmentation assumption (CTRL-006) stands in the way.
- Impact: confidentiality
- 2/5
- Command payloads carry limited PHI.
- Impact: integrity
- 5/5
- Unauthorized modification of delivered dose; direct falsification of therapy.
- Impact: availability
- 5/5
- Malicious commands can halt or exhaust delivery on the active channel.
- Impact: authenticity
- 5/5
- Command origin cannot be attributed to an authorized clinician.
- Safety consequence
- Potential hazardous situation
- Over/under-delivery scenario referred to ISO 14971 file HZ-0141; confirmed potential hazardous situation by Clinical Safety.
- Affected scope
- Multi patient
- Any connected NP-200 with remote commands enabled; multi-patient reach via shared clinical environment.
- Detectability
- 2/5
- No command-origin audit distinguishable from legitimate traffic today; weak detection.
- Uncertainty
- Low
- Two corroborating sources; API behavior reproduced in test harness.
Inherent Critical 20 = L4 x I5 per MTX-2026-01. Impact aggregated as max(C2,I5,A5,Au5) with dimensions retained. Cyber exploitability is not equated to probability of harm (DR-TST-024).
- Threat
- TV-000118
- Assessor
- Marcus Chen
- Assessed
- 16 Apr 2026, 09:05 UTC
- Method / matrix
- RM-5x5 v2.1 · MTX-2026-01