PT-2024-33307 · Unknown · Ventilator

Published

2024-11-14

·

Updated

2024-11-15

·

CVE-2024-48973

CVSS v3.1

9.3

Critical

VectorAV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ventilator (affected versions not specified)
Description The ventilator's serial interface has its debug port enabled by default, allowing an attacker to send and receive unencrypted messages. This could result in unauthorized disclosure of information and have unintended impacts on device settings and performance.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

CVE-2024-48973

Affected Products

Ventilator