CVE-2024-48971

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventilator and use it to gain unauthorized access to the device, with clinician privileges.
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-14 22:15

Updated : 2024-11-15 13:58


NVD link : CVE-2024-48971

Mitre link : CVE-2024-48971

CVE.ORG link : CVE-2024-48971


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials