ICS Medical Advisories
by Cisagov
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-9832 | Cri | 0.60 | 9.3 | 0.00 | Nov 14, 2024 | There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to device settings that… | ||
| CVE-2025-27714 | Med | 0.41 | 6.3 | 0.00 | Aug 21, 2025 | An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise. | ||
| CVE-2025-24489 | Med | 0.41 | 6.3 | 0.00 | Aug 21, 2025 | An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise. | ||
| CVE-2024-53683 | Med | 0.29 | 4.4 | 0.00 | Jan 17, 2025 | A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use. | ||
| CVE-2024-54681 | Low | 0.23 | 3.5 | 0.00 | Jan 17, 2025 | Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application. |
- risk 0.60cvss 9.3epss 0.00
There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker could execute a brute-force attack to gain unauthorized access to the ventilator, and then make changes to device settings that…
- risk 0.41cvss 6.3epss 0.00
An attacker could exploit this vulnerability by uploading arbitrary files via the a specific endpoint, leading to unauthorized remote code execution or system compromise.
- risk 0.41cvss 6.3epss 0.00
An attacker could exploit this vulnerability by uploading arbitrary files via a specific service, which could lead to system compromise.
- risk 0.29cvss 4.4epss 0.00
A valid set of credentials in a .js file and a static token for communication were obtained from the decompiled IPA. An attacker could use the information to disrupt normal use of the application by changing the translation files and thus weaken the integrity of normal use.
- risk 0.23cvss 3.5epss 0.00
Multiple bash files were present in the application's private directory. Bash files can be used on their own, by an attacker that has already full access to the mobile platform to compromise the translations for the application.