CVE-2024-48973
CRITICALDescription
The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.
CVSS v3.1 Score
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2024-48973? +
How severe is CVE-2024-48973? +
How do I check if I'm vulnerable to CVE-2024-48973? +
Related Vulnerabilities
Securing externally available CAN wires can easily allow physical access to the CAN bus, allowing possible injection of specially formed …
Certain software builds for the BLU View 2 and Sharp Rouvo V Android devices contain a vulnerable pre-installed app with …
eLinkSmart Hidden Smart Cabinet Lock 2024-05-22 has Incorrect Access Control and fails to perform an authorization check which can lead …
A vulnerability was found in INSTAR 2K+ and 4K 3.11.1 Build 1124. This issue affects some unknown processing of the …
Incorrect Access Control in ASUS RT-N12+ B1 and RT-N12 D1 routers allows local attackers to obtain root terminal access via …
Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login …