CVE-2024-48973: Baxter LIFE2000 Ventilation System
Critical severity, CVSS 9.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see 3.2.1) that result in unauthorized disclosure of information and/or have unintended impacts on device settings and performance.
Affected products
- Baxter LIFE2000 Ventilation System: up to and including 06.08.00.00
- Baxter LIFE2000 Ventilator Firmware: up to and including 06.08.00.00
Published 2024-11-14. Last modified 2026-06-17.