Ravi Patel, Customer Admin

NP-200 system security design review

NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007

PRJ-2026-0042-DRV-0001Threat review
Threat workbench

Rogue device impersonates clinician app over BLE pairing

PRJ-2026-0042-TV-000126AssessedHigh

  1. Proposed (passed)
  2. Confirmed (passed)
  3. Assessed (current)
  4. Treatment planned (pending)
  5. Mitigation pending (pending)
  6. Verified (pending)
  7. Closed (pending)

Legacy Just Works pairing on rev A hardware (CTRL-002) lets a nearby attacker pair a rogue peripheral that impersonates the clinician mobile app, gaining the app-facing GATT surface including infusion review and command initiation requests.

Deterministic ruleConfidence medium

Actor: Proximity attacker with BLE tooling; low-to-moderate skill.

Elements
AE-000046BLE interface controllerAE-000052Clinician mobile app
Flows
DF-000071BLE clinician session
Sources
SRC-0001VSDX page 3 connector 74
Function
Clinician session channel at the device perimeter