CVE-2024-48966 describes a critical vulnerability in the service tools used for ventilator testing and calibration, affecting an unspecified product. The vulnerability, rated 10.0 CVSS (Critical), stems from a lack of user authentication in these tools, allowing an unauthenticated attacker with access to the Service PC to obtain diagnostic information or manipulate ventilator settings and embedded software. There is no evidence of active exploitation, public exploit code, or inclusion in the CISA KEV catalog, though it has garnered significant community discussion with 10 mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Baxter | Life2000 Ventilation System | 06.08.00.00 and priorCNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.