#VU100609 Missing Authentication for Critical Function in Life2000 Ventilation System - CVE-2024-48966

 

#VU100609 Missing Authentication for Critical Function in Life2000 Ventilation System - CVE-2024-48966

Published: November 19, 2024


Vulnerability identifier: #VU100609
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2024-48966
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Life2000 Ventilation System
Software vendor:
Baxter

Description

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the software tools used by service personnel to test & calibrate the ventilator do not support user authentication. A remote attacker can obtain diagnostic information through the test tool or manipulate the ventilator's settings and embedded software.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links