The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.
History

Fri, 15 Nov 2024 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Baxter
Baxter life2000 Ventilator Firmware
CPEs cpe:2.3:o:baxter:life2000_ventilator_firmware:*:*:*:*:*:*:*:*
Vendors & Products Baxter
Baxter life2000 Ventilator Firmware
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 14 Nov 2024 21:30:00 +0000

Type Values Removed Values Added
Description The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.
Title Clinician Password and Serial Number Clinician Password are hard-coded in Life2000 Ventilator
Weaknesses CWE-798
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Baxter

Published: 2024-11-14T21:13:36.036Z

Updated: 2024-11-15T21:06:24.325Z

Reserved: 2024-10-10T19:24:41.495Z

Link: CVE-2024-48971

cve-icon Vulnrichment

Updated: 2024-11-15T21:06:19.382Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-14T22:15:18.327

Modified: 2024-11-15T13:58:08.913

Link: CVE-2024-48971

cve-icon Redhat

No data.