Description
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43154 | The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance. |
References
History
Fri, 15 Nov 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baxter
Baxter life2000 Ventilator Firmware |
|
| CPEs | cpe:2.3:o:baxter:life2000_ventilator_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Baxter
Baxter life2000 Ventilator Firmware |
|
| Metrics |
ssvc
|
Thu, 14 Nov 2024 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance. | |
| Title | Life2000 ventilator and Service PC lack sufficient audit logging capabilities | |
| Weaknesses | CWE-778 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Baxter
Published:
Updated: 2024-11-15T14:28:13.605Z
Reserved: 2024-10-10T19:24:34.436Z
Link: CVE-2024-48967
Updated: 2024-11-15T14:27:46.856Z
Status : Awaiting Analysis
Published: 2024-11-14T22:15:17.927
Modified: 2024-11-15T13:58:08.913
Link: CVE-2024-48967
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD