Description

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to device settings that could disrupt the function of the device and/or result in unauthorized information disclosure.

INFO

Published Date :

2024-11-14T21:03:16.721Z

Last Modified :

2024-11-18T15:37:00.311Z

Source :

Baxter
AFFECTED PRODUCTS

The following products are affected by CVE-2024-9832 vulnerability.

Vendors Products
Baxter
  • Life2000 Ventilator Firmware
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2024-9832.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact