CVE-2024-48971

CRITICAL

Baxter Life2000 Ventilation System < 06.08.00.00 - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.

References (1)

Core 1
Core References

Scores

CVSS v3 9.3
EPSS 0.0022
EPSS Percentile 12.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-798
Status published
Products (1)
Baxter/Life2000 Ventilation System 06.08.00.00 and prior
Published Nov 14, 2024
Tracked Since Feb 18, 2026