CVE-2024-48970

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 1191

Summary

CVE-2024-48970 is a vulnerability affecting certain medical ventilators. The issue lies in the ventilator's microcontroller, which lacks memory protection. An attacker with physical access to the device can connect to the JTAG interface using an off-the-shelf debugging tool, allowing them to read or write to the flash memory. This vulnerability poses a risk of disrupting the device's function and potentially causing unauthorized information disclosure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share