The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.
The debug port on the ventilator's serial interface is active by default and does not require authentication. Communication through this port is unencrypted, which means that an attacker with physical access to the device can freely intercept transmitted data and send their own commands. The consequence can be both unauthorized reading of diagnostic and configuration information and modification of device settings and behavior.
An attacker can gain unauthorized access to information transmitted through the serial interface and influence the settings and operation of the ventilator, which in a medical environment can pose a direct threat to patient life.
Apply patches available from the manufacturer according to references. As a temporary measure, it is recommended to restrict physical access to the device's serial interface and verify whether the debug port can be disabled in the device configuration according to the manufacturer's recommendations described in the CISA ICSMA-24-319-01 advisory.
Ventilator (medical ventilator) indicated in the CISA ICS-CERT ICSMA-24-319-01 advisory — specific versions indicated in manufacturer references
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H