NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Unauthenticated serial service port grants privileged shell
PRJ-2026-0042-TV-000101ClosedHigh
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (passed)
- Mitigation pending (passed)
- Verified (passed)
- Closed (current)
Baseline-era finding: the rev A serial service port exposed a privileged diagnostic shell without authentication. Mitigated under baseline DRB-0007 with authenticated maintenance access and port lockdown; closure evidence accepted and residual risk approved.
Deterministic ruleConfidence high
Actor: Bedside actor with a serial cable; low skill.
- Physical access to service port (pre-mitigation).
- Attach serial console.
- Receive privileged shell without credentials (pre-mitigation).
Inherent
HighL4 × I4
Residual
LowL1 × I4
Factors (1 to 5)
Exploitability4
Impact: confidentiality3
Impact: integrity4
Impact: availability3
Impact: authenticity3
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 4 | 20% |
| Impact: confidentiality | 3 | 15% |
| Impact: integrity | 4 | 20% |
| Impact: availability | 3 | 15% |
| Impact: authenticity | 3 | 15% |
| Detectability | 3 | 15% |
Safety consequence: NoneScope: Single deviceUncertainty: Low
- Exploitability
- 4/5
- Any bedside actor with a serial cable (pre-mitigation).
- Impact: confidentiality
- 3/5
- Full device data readable via shell.
- Impact: integrity
- 4/5
- Privileged configuration change possible.
- Impact: availability
- 3/5
- Device disable possible.
- Impact: authenticity
- 3/5
- Unattributed privileged actions.
- Safety consequence
- None
- Maintenance interlock prevents infusion during shell access.
- Affected scope
- Single device
- Physical access required per device.
- Detectability
- 3/5
- Console sessions logged after 3.1.4.
- Uncertainty
- Low
- Bench-verified.
Baseline-cycle assessment under method v2.0; retained immutable with the DRB-0007 as-of record (DR-SEC-018).
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- Not set
- Disposition
- Confirmed by Marcus Chen, 20 Jan 2026
- Treatment adopted (passed)
- Implemented (passed)
- Evidence accepted (passed)
- Retest passed (passed)
- Closed (passed)
- REM-105Authenticated maintenance access and service-port lockdownVerified
- VOB-000108Service-port lockdown retestVerifieddue 13 Feb 2026
EvidenceAcceptedRetestPassed
- Residual risk approved; threat closedElena Vasquez · Residual Low 4 accepted by risk owner + Quality.
- Retest passedsystem · VOB-000108 evidence EVA-000091 accepted.
- Mitigation implementedNoor Haddad · REM-105 authenticated maintenance access shipped in firmware 3.1.4.
- Confirmed (baseline cycle)Marcus Chen
SourceSRC-0001NP-200_SystemArchitecture.vsdx, page 4 shape 23MappedElementAE-000047Maintenance diagnostic serviceFlowDF-000084Maintenance diagnostic sessionThreatTV-000101Unauthenticated serial service portClosedRiskRSK-000101Inherent High 16 / residual Low 4 (effective)RemediationREM-105Authenticated maintenance accessVerifiedControlDC-000209Authenticated maintenance access requirementObligationVOB-000108Service-port lockdown retest (EVA-000091)Verified