Description
The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-43158 | The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure. |
References
History
Mon, 18 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Baxter
Baxter life2000 Ventilator Firmware |
|
| CPEs | cpe:2.3:o:baxter:life2000_ventilator_firmware:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Baxter
Baxter life2000 Ventilator Firmware |
|
| Metrics |
ssvc
|
Thu, 14 Nov 2024 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthorized changes to the device's configuration settings and/or compromise device functionality by pushing a compromised/illegitimate firmware file. This could disrupt the function of the device and/or cause unauthorized information disclosure. | |
| Title | Life2000 Ventilator does not perform proper file integrity checks when adopting firmware updates | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Baxter
Published:
Updated: 2024-11-18T15:32:38.488Z
Reserved: 2024-10-10T19:24:41.495Z
Link: CVE-2024-48974
Updated: 2024-11-18T15:32:27.939Z
Status : Awaiting Analysis
Published: 2024-11-14T22:15:18.727
Modified: 2024-11-15T13:58:08.913
Link: CVE-2024-48974
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD