The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debugging tool, which could disrupt the function of the device and/or cause unauthorized information disclosure.
An attacker with physical access to the device can connect to the internal JTAG interface using commonly available debugging tools. Since the ventilator microcontroller does not implement memory protection (no safeguards compliant with CWE-1191), it is possible to read and write to flash memory without any authentication mechanisms or access controls. Such access allows modification of the device firmware or reading of stored data.
An attacker can disrupt or completely disable the ventilator function, creating a direct threat to patient life, as well as gain unauthorized access to data stored in the device memory (unauthorized information disclosure).
Patches available from the manufacturer should be applied according to the references provided. Additionally, until patches are implemented, it is recommended to restrict physical access to devices to authorized personnel only, implement physical access controls (e.g., locked rooms, monitoring), and monitor devices for unauthorized hardware tampering. Detailed recommendations are contained in the CISA advisory ICSMA-24-319-01.
Mechanical ventilator (respiratory device) indicated in the CISA ICS-CERT advisory ICSMA-24-319-01 — specific models and versions listed in manufacturer references
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H