NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Unsigned application firmware package accepted by update agent
PRJ-2026-0042-TV-000112AssessedHigh
- Proposed (passed)
- Confirmed (passed)
- Assessed (current)
- Treatment planned (pending)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
An attacker able to influence the staged download path or a compromised distribution credential delivers a modified application firmware image. Bootloader-stage verification (CTRL-003) does not cover application images at every boot and no anti-rollback policy exists, so tampered or downgraded firmware could run on the pump.
Deterministic ruleConfidence high
Actor: Supply-path attacker or insider with distribution access; high skill; remote.
- Attacker can substitute or downgrade a package on DF-000082 before install.
- Application-image signature enforcement remains partial (CTRL-003).
- Obtain or forge a package accepted by the update agent (unsigned application payload).
- Trigger or await an update window (OPST-004).
- Update agent applies the image; rollback to a vulnerable version is not blocked.
- Flows
- DF-000082Firmware package delivery
- Function
- Firmware update and recovery path
Inherent
HighL3 × I5
Residual
Not projected
Factors (1 to 5)
Exploitability3
Impact: confidentiality3
Impact: integrity5
Impact: availability4
Impact: authenticity4
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 14% |
| Impact: confidentiality | 3 | 14% |
| Impact: integrity | 5 | 23% |
| Impact: availability | 4 | 18% |
| Impact: authenticity | 4 | 18% |
| Detectability | 3 | 14% |
Safety consequence: IndirectScope: Device fleetUncertainty: Medium
- Exploitability
- 3/5
- Requires supply-path position or distribution credential; staged rollout narrows the window.
- Impact: confidentiality
- 3/5
- Malicious firmware can read device-resident data.
- Impact: integrity
- 5/5
- Arbitrary code on the pump platform.
- Impact: availability
- 4/5
- Bricking/downgrade of fleet segments.
- Impact: authenticity
- 4/5
- Firmware provenance broken.
- Safety consequence
- Indirect
- Safety effect mediated by whatever the malicious image does; treated as indirect pending safety analysis.
- Affected scope
- Device fleet
- Distribution path reaches staged fleet cohorts.
- Detectability
- 3/5
- Version inventory exists; integrity telemetry partial.
- Uncertainty
- Medium
- Exact signing coverage of application images being confirmed against build evidence.
High 15 = L3 x I5. Blocking DR-RUL-004 until REM-210/211 decision is adopted or an authorized acceptance request exists.
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 29 May 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Risk assessed (RSK-000112)Marcus Chen · Inherent High 15. Blocking under DR-RUL-004 until a treatment decision is adopted.
- ConfirmedMarcus Chen
- Proposed by deterministic rule UPD-INT-01 (run TMR-0009)system