PT-2019-7128 · Baxter · Baxter Sigma Spectrum Infusion System

Published

2019-03-26

·

Updated

2019-10-09

·

CVE-2014-5432

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Baxter SIGMA Spectrum Infusion System version 6.05
Description The issue allows remote access via Port 22/SSH without authentication, enabling a remote attacker to make unauthorized configuration changes to the wireless battery module (WBM) and potentially access account credentials and shared keys. It is noted that this vulnerability does not allow control of the SIGMA Spectrum infusion pump from the WBM.
Recommendations For Baxter SIGMA Spectrum Infusion System version 6.05, update to Version 8, which incorporates necessary hardware and software changes to address the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2014-5432

Affected Products

Baxter Sigma Spectrum Infusion System