CVE-2024-48973

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 1263

Summary

CVE-2024-48973 is a newly disclosed vulnerability affecting certain medical ventilators. By default, these devices have an active debug port on their serial interface, which is unencrypted and open to attack. An adversary can exploit this weakness to send and receive data, potentially leading to unauthorized information disclosure and unintended consequences for device settings and performance. This issue poses a significant threat to patient safety and data confidentiality. Until a patch is released, it is recommended that affected organizations take immediate steps to secure the debug ports on their ventilators.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share