CVE-2024-48967
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.63%
- CWE
- CWE-778
- Published
- 2024-11-14
- Last modified
- 2026-03-13
Affected products
- Baxter Life2000 Ventilation System
Weakness type
Related vulnerabilities
- CVE-2026-66816 — Microsoft SQL Server Security Feature Bypass Vulnerability
- CVE-2026-82863 — @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
- CVE-2020-37268 — Coq and Rocq Prover Print Assumptions Omits Unsafe Universe Checking Inlined Through Parameter Inline
- CVE-2025-62307 — HCL IntelliOps Event Management is affected by multiple security vulnerabilities.
- CVE-2026-76208 — phpMyFAQ 3.1.0 through 4.1.6 Authentication Bypass via LDAP
- CVE-2026-41709 — ESX insufficient logging vulnerability
- CVE-2026-9247 — Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user...
- CVE-2026-32803 — Dell PowerScale OneFS versions 9.5.0.0 through 9.5.1.6, 9.6.0.0 through 9.7.1.13, 9.8.0.0 through...