PatchSiren cyber security CVE debrief
CVE-2024-9834 Baxter CVE debrief
A critical vulnerability (CVSS 9.3) in the Baxter Life2000 Ventilation System allows attackers with local access to the device's serial interface to send and receive unauthorized messages. This improper data protection flaw can result in information disclosure and unintended modifications to device settings and performance. The vulnerability affects Life2000 Ventilation System versions 6.08.00.00 and earlier. Baxter has not yet released a patch but plans a follow-up announcement in Q2 2025. No exploitation has been reported to date.
- Vendor
- Baxter
- Product
- Life2000 Ventilation System
- CVSS
- CRITICAL 9.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-14
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-14
Who should care
Healthcare facilities using Baxter Life2000 Ventilation Systems, biomedical engineering teams, clinical engineering departments, and healthcare CISOs responsible for medical device security.
Technical summary
The Baxter Life2000 Ventilation System fails to properly protect data on its serial interface, allowing an attacker with physical access to send and receive messages without authorization. This can lead to unauthorized information disclosure and manipulation of device settings affecting performance. The attack requires local access (AV:L) but no privileges (PR:N) and can impact system-wide availability, confidentiality, and integrity.
Defensive priority
critical
Recommended defensive actions
- Restrict physical access to Life2000 ventilators; do not leave devices unattended in public or unsecured areas per vendor guidance.
- Monitor for Q2 2025 vendor follow-up announcement regarding patch availability.
- Apply network segmentation and access controls to limit exposure of device serial interfaces.
- Review CISA ICS recommended practices for medical device security.
Evidence notes
CISA published ICSMA-24-319-01 on 2024-11-14 identifying improper data protection on the ventilator's serial interface as the root cause. CVSS 3.1 vector AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H confirms local attack vector with no privileges required but high impact across confidentiality, integrity, and availability.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-9834 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-9834
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-9834 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-9834
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-319-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-319-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.