PatchSiren cyber security CVE debrief
CVE-2024-48974 Baxter CVE debrief
A critical vulnerability in the Baxter Life2000 Ventilation System allows attackers to push compromised firmware due to missing file integrity checks during updates. Published November 14, 2024, this flaw enables unauthorized configuration changes, device functionality compromise, and potential information disclosure. The CVSS 9.3 score reflects local attack vector with no privileges required, high confidentiality/integrity/availability impact, and scope change affecting resources beyond the vulnerable component. Baxter has not yet released a patch but plans a follow-up announcement in Q2 2025. No exploitation has been reported.
- Vendor
- Baxter
- Product
- Life2000 Ventilation System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-14
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-14
Who should care
Healthcare delivery organizations using Baxter Life2000 Ventilation Systems; biomedical engineering teams; clinical engineering departments; hospital security operations centers; medical device cybersecurity programs; critical care units dependent on ventilator availability
Technical summary
The Life2000 Ventilation System fails to validate firmware file integrity during update adoption. An attacker with local physical access can install malicious firmware, forcing unauthorized configuration changes or complete device functionality compromise. The vulnerability scores CVSS 9.3 (Critical) with local attack vector, low attack complexity, no privileges required, and high impacts across confidentiality, integrity, and availability with scope change. Affected versions: 06.08.00.00 and earlier. No patch available; vendor mitigation requires physical security controls.
Defensive priority
critical
Recommended defensive actions
- Maintain physical possession and control of Life2000 ventilators; do not leave devices unattended in public or unsecured areas to reduce malicious actor access risk
- Monitor for Baxter's Q2 2025 follow-up announcement regarding vulnerability remediation
- Apply vendor firmware updates immediately upon release when available
- Implement network segmentation for medical devices per CISA ICS recommended practices
- Review and enforce least-privilege access controls for device maintenance personnel
Evidence notes
Source: CISA ICS Medical Advisory ICSMA-24-319-01. Affected product: Baxter Life2000 Ventilation System version 06.08.00.00 and earlier. CVSS 3.1 vector: AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-48974 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-48974
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-48974 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-48974
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-319-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.