Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Attacker sends unauthorized dosing command

PRJ-2026-0042-TV-000118Mitigation pendingCriticalSafety-linked

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (passed)
  4. Treatment planned (passed)
  5. Mitigation pending (current)
  6. Verified (pending)
  7. Closed (pending)

An attacker with a foothold on the hospital clinical network reaches the NP command API exposed through the NimbusLink Gateway and submits a crafted dosing command. The candidate source declares POST /dose without a security scheme, so the dosing command processor would accept and sequence a command that no clinician authorized, altering infusion delivery for the connected patient.

Safety-linkedDeterministic ruleConfidence high

Actor: Network-resident attacker (compromised hospital host or rogue device on VLAN 12); moderate skill, commodity tooling; no physical access required.

Elements
AE-000042Infusion dosing command processorAE-000041Pump motor controllerAE-000051NimbusLink Gateway edge service
Flows
DF-000077Remote dosing commandDF-000073Dosing actuation
Sources
SRC-0001VSDX page 3 connector 81SRC-0002OpenAPI POST /dose (line 214)
Function
Infusion dosing delivery (safety-relevant command path)