PT-2020-12982 · Baxter · Baxter Exactamix Em 2400+1
Published
2020-06-29
·
Updated
2020-07-07
·
CVE-2020-12012
CVSS v3.1
6.1
Medium
| Vector | AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Baxter ExactaMix EM 2400 versions 1.10 through 1.14
Baxter ExactaMix EM 1200 versions 1.1 through 1.5
Description
The ExactaMix application has hard-coded administrative account credentials. Successful exploitation of this issue may allow an attacker with physical access to gain unauthorized access to view or update system configuration or data, potentially impacting confidentiality and integrity and risking exposure of sensitive information, including Protected Health Information (PHI).
Recommendations
For Baxter ExactaMix EM 2400 versions 1.10 through 1.14, consider changing the hard-coded administrative account credentials to unique, secure credentials.
For Baxter ExactaMix EM 1200 versions 1.1 through 1.5, consider changing the hard-coded administrative account credentials to unique, secure credentials.
As a temporary workaround, restrict physical access to the system to minimize the risk of exploitation.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baxter Exactamix Em1200
Baxter Exactamix Em 2400