PT-2020-12982 · Baxter · Baxter Exactamix Em 2400+1

Published

2020-06-29

·

Updated

2020-07-07

·

CVE-2020-12012

CVSS v3.1

6.1

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Baxter ExactaMix EM 2400 versions 1.10 through 1.14 Baxter ExactaMix EM 1200 versions 1.1 through 1.5
Description The ExactaMix application has hard-coded administrative account credentials. Successful exploitation of this issue may allow an attacker with physical access to gain unauthorized access to view or update system configuration or data, potentially impacting confidentiality and integrity and risking exposure of sensitive information, including Protected Health Information (PHI).
Recommendations For Baxter ExactaMix EM 2400 versions 1.10 through 1.14, consider changing the hard-coded administrative account credentials to unique, secure credentials. For Baxter ExactaMix EM 1200 versions 1.1 through 1.5, consider changing the hard-coded administrative account credentials to unique, secure credentials. As a temporary workaround, restrict physical access to the system to minimize the risk of exploitation.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12012

Affected Products

Baxter Exactamix Em1200
Baxter Exactamix Em 2400