NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Rogue device impersonates clinician app over BLE pairing
PRJ-2026-0042-TV-000126AssessedHigh
- Proposed (passed)
- Confirmed (passed)
- Assessed (current)
- Treatment planned (pending)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
Legacy Just Works pairing on rev A hardware (CTRL-002) lets a nearby attacker pair a rogue peripheral that impersonates the clinician mobile app, gaining the app-facing GATT surface including infusion review and command initiation requests.
Deterministic ruleConfidence medium
Actor: Proximity attacker with BLE tooling; low-to-moderate skill.
- Physical proximity to the bedside device.
- Rev A hardware without numeric-comparison pairing.
- Initiate pairing during a session window using Just Works.
- Impersonate the app GATT client to AE-000046.
- Issue app-level requests limited only by application logic.
Inherent
HighL3 × I3
Residual
Not projected
Factors (1 to 5)
Exploitability3
Impact: confidentiality3
Impact: integrity3
Impact: availability2
Impact: authenticity3
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 18% |
| Impact: confidentiality | 3 | 18% |
| Impact: integrity | 3 | 18% |
| Impact: availability | 2 | 12% |
| Impact: authenticity | 3 | 18% |
| Detectability | 3 | 18% |
Safety consequence: NoneScope: Device fleetUncertainty: Medium
- Band override: Medium 9 to HighOverrideMarcus Chen · Fleet-wide pairing weakness on rev A hardware; conservative banding held until field-population data narrows uncertainty (method 21.5: override retains calculation history). Approved by Priya Raman.
- Exploitability
- 3/5
- Requires proximity and a pairing window; public tooling exists for comparable stacks.
- Impact: confidentiality
- 3/5
- Session data and infusion status visible to the impersonator.
- Impact: integrity
- 3/5
- App-level requests possible; command initiation still passes processor validation.
- Impact: availability
- 2/5
- Can disrupt the legitimate app session.
- Impact: authenticity
- 3/5
- Peer identity of the app channel broken.
- Safety consequence
- None
- Processor-side validation and local confirmation stand between impersonation and delivery.
- Affected scope
- Device fleet
- All rev A hardware units share the pairing weakness.
- Detectability
- 3/5
- Pairing anomalies observable in device logs.
- Uncertainty
- Medium
- Field prevalence of rev A units under quantification; conservative treatment applied.
Calculated Medium 9 = L3 x I3; displayed band High by approved manual override. Original calculation retained and reproducible.
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 12 Jun 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (current)
- Implemented (pending)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-212BLE secure pairing with app-layer session bindingEvaluating
EvidenceNot requestedRetestNot scheduled
- Override approvedPriya Raman · Independent approval recorded; calculation history retained.
- Manual band override proposedMarcus Chen · Calculated Medium 9 raised to High: fleet-wide pairing weakness, conservative pending field data.
- ConfirmedMarcus Chen
- Proposed by deterministic rule IFC-AUTH-04 (run TMR-0009)system