CVE-2024-48970: critical vulnerability in Baxter Life2000 Ventilation System
Life2000 Ventilator microcontroller lacks memory protection
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A Life2000 ventilator's microcontroller has no memory protection, allowing someone with physical access to connect a debugging tool to its internal JTAG port and read or modify its memory, potentially disrupting the device or stealing sensitive data.
The microcontroller lacks memory protection mechanisms, enabling direct memory access via the exposed JTAG interface using standard debugging tools. An attacker with physical access can read/write flash memory, compromising device integrity and confidentiality. This may lead to unauthorized firmware modification or extraction of protected information.
In the same product, most dangerous first.