Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Unsigned application firmware package accepted by update agent

PRJ-2026-0042-TV-000112AssessedHigh

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (current)
  4. Treatment planned (pending)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

An attacker able to influence the staged download path or a compromised distribution credential delivers a modified application firmware image. Bootloader-stage verification (CTRL-003) does not cover application images at every boot and no anti-rollback policy exists, so tampered or downgraded firmware could run on the pump.

Deterministic ruleConfidence high

Actor: Supply-path attacker or insider with distribution access; high skill; remote.

Elements
AE-000045Firmware update agentAE-000062Fleet update distribution service
Flows
DF-000082Firmware package delivery
Sources
SRC-0001VSDX page 5 connector 17SRC-0003CycloneDX components bootld-verify 2.1 / updlib 3.4
Function
Firmware update and recovery path