#VU100594 Improper Physical Access Control in Life2000 Ventilation System - CVE-2024-48973
Published: November 18, 2024
Life2000 Ventilation System
Baxter
Description
The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to the debug port on the ventilator's serial interface is enabled by default. A local attacker can send and receive specially crafted messages over the debug port to gain access to sensitive information, leading to unintended impact on device settings and performance.