PatchSiren cyber security CVE debrief
CVE-2024-9834 Baxter CVE debrief
A critical vulnerability (CVSS 9.3) in the Baxter Life2000 Ventilation System allows attackers with local access to the device's serial interface to send and receive unauthorized messages. This improper data protection flaw can result in information disclosure and unintended modifications to device settings and performance. The vulnerability affects Life2000 Ventilation System versions 6.08.00.00 and earlier. Baxter has not yet released a patch but plans a follow-up announcement in Q2 2025. No exploitation has been reported to date.
- Vendor
- Baxter
- Product
- Life2000 Ventilation System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-14
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-14
Who should care
Healthcare facilities using Baxter Life2000 Ventilation Systems, biomedical engineering teams, clinical engineering departments, and healthcare CISOs responsible for medical device security.
Technical summary
The Baxter Life2000 Ventilation System fails to properly protect data on its serial interface, allowing an attacker with physical access to send and receive messages without authorization. This can lead to unauthorized information disclosure and manipulation of device settings affecting performance. The attack requires local access (AV:L) but no privileges (PR:N) and can impact system-wide availability, confidentiality, and integrity.
Defensive priority
critical
Recommended defensive actions
- Restrict physical access to Life2000 ventilators; do not leave devices unattended in public or unsecured areas per vendor guidance.
- Monitor for Q2 2025 vendor follow-up announcement regarding patch availability.
- Apply network segmentation and access controls to limit exposure of device serial interfaces.
- Review CISA ICS recommended practices for medical device security.
Evidence notes
CISA published ICSMA-24-319-01 on 2024-11-14 identifying improper data protection on the ventilator's serial interface as the root cause. CVSS 3.1 vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H confirms local attack vector with no privileges required but high impact across confidentiality, integrity, and availability.
Official resources
-
CVE-2024-9834 CVE record
CVE.org
-
CVE-2024-9834 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-11-14