CINEOS Clinical Exposure Watch · CEW
CINEOS turns public advisories, CVEs, manufacturer publications, dependency records, and authorized validation evidence into decision-ready findings — clearly separating confirmed facts from open questions.
Passive by default. Public-source evidence first. No device probing, scanning, exploitation, authentication testing, or patient-care disruption.
See the actual output
Demonstration finding based on public sources. Manufacturer and product identifiers are withheld from this public page pending responsible-disclosure and legal review. The named, evidence-linked version is available to qualified prospects under NDA.
Why Observe, not higher: new public signal; no confirmed exposed asset. It would be dishonest to grade this Act or Urgent without observing exposure — so we don't.
| CVE | CVSS | Weakness |
|---|---|---|
| CVE-2017-12718 | 8.1 | CWE-120 · buffer overflow |
| CVE-2017-12720 | 8.1 | CWE-306 · missing authentication |
| CVE-2017-12724 | 8.1 | CWE-798 · hard-coded credentials |
| CVE-2017-12726 | 7.3 | CWE-798 · hard-coded credentials |
| CVE-2017-12721 | 5.9 | CWE-295 · improper certificate validation |
| CVE-2017-12725 | 5.6 | CWE-798 · hard-coded credentials |
| CVE-2017-12722 | 5.3 | CWE-125 · out-of-bounds read |
| CVE-2017-12723 | 3.7 | CWE-200 · information exposure |
Evidence-based escalation
Four tiers, decided by explainable gates — not a black-box score. A finding rises only when the evidence earns it, and it arrives with the reasoning that put it there.
Trigger
Public signal; no confirmed device linkage. → Monitor & enrich.
Trigger
Strong public link to a manufacturer / device. → Manufacturer security review.
Trigger
Exposed pathway + relevant advisory or control plane. → Security, clinical eng, vendor.
Trigger
Active exploitation or likely care-impact path. → Incident response & exec escalation.
Transparency under imperfection
Every record declares how it was obtained. When something can't be fully verified, we say so plainly rather than paper over it. That honesty repeats across every finding.
Retrieved HTTP 200 from the public NVD API and hashed. sha256:6b1e…verifiable at nvd.nist.gov
The advisory host blocked automated retrieval (HTTP 403), so it is referenced by URL, not yet content-hashed. Recorded honestly — not fabricated.
What you get
Per product family, from public sources.
Declared vs. observable footprint.
Daily; only what links to your graph.
An action and an owner, not a number.
Counsel-safe, disclosure-ready.
Who it's for
Same evidence discipline, framed to the question each team has to answer.
Which public signals, dependencies, and exposure indicators may affect our product family?
Review the manufacturer workflowWhich advisories are relevant to equipment we have authorized you to assess?
Review the health-system workflowWhich medical-device exposure conditions are changing across an insured or portfolio population?
Discuss portfolio intelligenceThe hard boundary
The default product observes public record and preserves evidence. It never touches your environment. Active validation, if ever wanted, is a separate written-authorization engagement — legal review, named assets, safety controls, emergency stop — never our default.
The business model, in one sentence
This finding is Observe because it rests on public record alone. Paid engagement determines external reachability.
A 30-day diagnostic for one product family — three proof-grade findings and a disclosure-ready remediation map. Not a subscription.
Know what changed. Know what is proven. Know who should act.