CVE-2024-9832

CVSS 3.1 Score 9.3 of 10 (high)

Details

Published Nov 14, 2024
Updated: Nov 15, 2024
CWE ID 307

Summary

CVE-2024-9832 is a vulnerability affecting certain medical ventilators. The issue allows an unlimited number of failed login attempts for the Clinician Password and the Serial Number Clinician Password. An attacker could exploit this vulnerability by carrying out a brute-force attack to gain unauthorized access to the ventilator. Successful exploitation could result in making changes to device settings, potentially disrupting their function and leading to unauthorized information disclosure. This vulnerability poses a significant risk to patient safety and confidentiality. It is crucial for ventilator manufacturers and healthcare organizations to apply the necessary patches to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share