The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information disclosure.
History

Mon, 18 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Baxter
Baxter life2000 Ventilator Firmware
CPEs cpe:2.3:o:baxter:life2000_ventilator_firmware:*:*:*:*:*:*:*:*
Vendors & Products Baxter
Baxter life2000 Ventilator Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 21:45:00 +0000

Type Values Removed Values Added
Description The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information disclosure.
Title Life2000 Ventilator microcontroller lacks memory protection
Weaknesses CWE-1191
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Baxter

Published: 2024-11-14T21:31:14.701Z

Updated: 2024-11-18T15:23:48.292Z

Reserved: 2024-10-10T19:24:41.494Z

Link: CVE-2024-48970

cve-icon Vulnrichment

Updated: 2024-11-18T15:23:26.571Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-14T22:15:18.137

Modified: 2024-11-15T13:58:08.913

Link: CVE-2024-48970

cve-icon Redhat

No data.