The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43156 | The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 15 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baxter
Baxter life2000 Ventilator Firmware |
|
| CPEs | cpe:2.3:o:baxter:life2000_ventilator_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Baxter
Baxter life2000 Ventilator Firmware |
|
| Metrics |
ssvc
|
Thu, 14 Nov 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges. | |
| Title | Clinician Password and Serial Number Clinician Password are hard-coded in Life2000 Ventilator | |
| Weaknesses | CWE-798 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Baxter
Published:
Updated: 2024-11-15T21:06:24.325Z
Reserved: 2024-10-10T19:24:41.495Z
Link: CVE-2024-48971
Updated: 2024-11-15T21:06:19.382Z
Status : Awaiting Analysis
Published: 2024-11-14T22:15:18.327
Modified: 2024-11-15T13:58:08.913
Link: CVE-2024-48971
No data.
OpenCVE Enrichment
No data.
EUVD