Vulnerability Description
The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.
CVSS Score
CRITICAL
Related Weaknesses (CWE)
References
FAQ
What is CVE-2024-48971?
CVE-2024-48971 is a vulnerability with a CVSS score of 9.3 (CRITICAL). The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to g...
How severe is CVE-2024-48971?
CVE-2024-48971 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-48971?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.