PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-9834 Baxter CVE debrief

A critical vulnerability (CVSS 9.3) in the Baxter Life2000 Ventilation System allows attackers with local access to the device's serial interface to send and receive unauthorized messages. This improper data protection flaw can result in information disclosure and unintended modifications to device settings and performance. The vulnerability affects Life2000 Ventilation System versions 6.08.00.00 and earlier. Baxter has not yet released a patch but plans a follow-up announcement in Q2 2025. No exploitation has been reported to date.

Vendor
Baxter
Product
Life2000 Ventilation System
CVSS
CRITICAL 9.3
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-14
Original CVE updated
2024-11-14
Advisory published
2024-11-14
Advisory updated
2024-11-14

Who should care

Healthcare facilities using Baxter Life2000 Ventilation Systems, biomedical engineering teams, clinical engineering departments, and healthcare CISOs responsible for medical device security.

Technical summary

The Baxter Life2000 Ventilation System fails to properly protect data on its serial interface, allowing an attacker with physical access to send and receive messages without authorization. This can lead to unauthorized information disclosure and manipulation of device settings affecting performance. The attack requires local access (AV:L) but no privileges (PR:N) and can impact system-wide availability, confidentiality, and integrity.

Defensive priority

critical

Recommended defensive actions

  • Restrict physical access to Life2000 ventilators; do not leave devices unattended in public or unsecured areas per vendor guidance.
  • Monitor for Q2 2025 vendor follow-up announcement regarding patch availability.
  • Apply network segmentation and access controls to limit exposure of device serial interfaces.
  • Review CISA ICS recommended practices for medical device security.

Evidence notes

CISA published ICSMA-24-319-01 on 2024-11-14 identifying improper data protection on the ventilator's serial interface as the root cause. CVSS 3.1 vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H confirms local attack vector with no privileges required but high impact across confidentiality, integrity, and availability.

Official resources

2024-11-14