CRITICAL🇵🇱 Wersja polska

CVE-2024-48973

CVSS 9.3v3.1pub. 2024-11-14upd. 2026-04-15

The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.

🤖 AI Analysis
How it works

The debug port on the ventilator's serial interface is active by default and does not require authentication. Communication through this port is unencrypted, which means that an attacker with physical access to the device can freely intercept transmitted data and send their own commands. The consequence can be both unauthorized reading of diagnostic and configuration information and modification of device settings and behavior.

Impact

An attacker can gain unauthorized access to information transmitted through the serial interface and influence the settings and operation of the ventilator, which in a medical environment can pose a direct threat to patient life.

Mitigation & patch

Apply patches available from the manufacturer according to references. As a temporary measure, it is recommended to restrict physical access to the device's serial interface and verify whether the debug port can be disabled in the device configuration according to the manufacturer's recommendations described in the CISA ICSMA-24-319-01 advisory.

Who is affected

Ventilator (medical ventilator) indicated in the CISA ICS-CERT ICSMA-24-319-01 advisory — specific versions indicated in manufacturer references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References