The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent…
Baxter·CWE-778·Published 2024-11-14
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance.
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with access to the ventilator and/or the Service PC could, without detection, make unauthorized changes to ventilator settings that result in unauthorized disclosure of information and/or have unintended impacts on device performance.
El respirador y la PC de servicio carecen de capacidades de registro de auditoría suficientes para permitir la detección de actividad maliciosa y el posterior examen forense. Un atacante con acceso al respirador o a la PC de servicio podría, sin ser detectado, realizar cambios no autorizados en la configuración del respirador que resulten en la divulgación no autorizada de información o tengan impactos no deseados en el rendimiento del dispositivo.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 10.0 | — | — | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
| 3.1 | Secondary | NVD | 10.0 | 3.9 | 6.0 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |