NP-200 system security design review
NimbusPump NP-200 Program · candidate AREV-0004 vs effective baseline DRB-0007
PRJ-2026-0042-DRV-0001Threat review
Threat workbench
Tampered drug library uploaded from compromised pharmacy workstation
PRJ-2026-0042-TV-000129Treatment plannedHighSafety-linked
- Proposed (passed)
- Confirmed (passed)
- Assessed (passed)
- Treatment planned (current)
- Mitigation pending (pending)
- Verified (pending)
- Closed (pending)
An attacker controlling the pharmacy drug-library workstation pushes a modified library over DF-000079. Altered concentration limits or care-area profiles silently change dose validation bounds on every device receiving the library, a fleet-wide safety-relevant integrity failure.
Safety-linkedDeterministic ruleConfidence high
Actor: Attacker with workstation compromise or malicious insider; moderate skill.
- LibraryManager workstation compromised.
- End-to-end package signing not enforced on the push path.
- Compromise pharmacy workstation running LibraryManager 4.0.
- Author a library with altered hard/soft limits.
- Push across TB-003; devices apply the library after transport-only checks.
Inherent
HighL3 × I5
Residual
MediumL1 × I5
Factors (1 to 5)
Exploitability3
Impact: confidentiality1
Impact: integrity5
Impact: availability3
Impact: authenticity4
Detectability3
| Category | Value | Share |
|---|---|---|
| Exploitability | 3 | 16% |
| Impact: confidentiality | 1 | 5% |
| Impact: integrity | 5 | 26% |
| Impact: availability | 3 | 16% |
| Impact: authenticity | 4 | 21% |
| Detectability | 3 | 16% |
Safety consequence: Potential hazardous situationScope: Device fleetUncertainty: LowSafety-risk linkage: confirmed
- Exploitability
- 3/5
- Requires workstation compromise; pharmacy endpoints historically targeted; push path then trusted.
- Impact: confidentiality
- 1/5
- Library content is not confidential.
- Impact: integrity
- 5/5
- Dose validation bounds silently altered fleet-wide.
- Impact: availability
- 3/5
- Bad library can force devices into safe-hold.
- Impact: authenticity
- 4/5
- Library provenance unverifiable end-to-end.
- Safety consequence
- Potential hazardous situation
- Wrong-limit delivery scenario; ISO 14971 file HZ-0146 opened by Clinical Safety.
- Affected scope
- Device fleet
- Library distribution reaches every subscribed device.
- Detectability
- 3/5
- Library version diffs reviewable, content diffs not surfaced today.
- Uncertainty
- Low
- Push path confirmed with R&D.
High 15 = L3 x I5; safety-linked; treatment adopted (REM-208).
- Responsible implementer
- Noor Haddad (Firmware Engineer)
- Accountable manager
- Tomas Novak
- Independent security reviewer
- Priya Raman
- Risk owner
- Marcus Chen
- Target date
- 19 Jun 2026
- Disposition
- Confirmed by Marcus Chen, 15 Apr 2026
- Treatment adopted (passed)
- Implemented (current)
- Evidence accepted (pending)
- Retest passed (pending)
- Closed (pending)
- REM-208Signed drug-library packages with version pinningAdopted
- VOB-000215Drug-library signature verification testIn progressdue 26 Jun 2026
EvidenceNot requestedRetestNot scheduled
- Treatment adoptedTomas Novak · REM-208 signed drug-library packages with version pinning; VOB-000215 in progress.
- Safety linkage reviewDr. Lena Fischer · Potential hazardous situation (wrong-limit delivery); ISO 14971 file HZ-0146 referenced.
- ConfirmedMarcus Chen
- Proposed by deterministic rule DST-INT-03 (run TMR-0009)system
SourceSRC-0001NP-200_SystemArchitecture.vsdx, page 2 connector 55MappedElementAE-000043Drug library storeFlowDF-000079Drug library push (crosses TB-003)ThreatTV-000129Tampered drug library uploadedTreatment plannedRiskRSK-000129Inherent High 15 / residual Medium 5 (projected)RemediationREM-208Signed drug-library packages + version pinningAdoptedControlDC-000318Drug-library signing requirementObligationVOB-000215Drug-library signature verification testIn progress