PT-2020-12984 · Baxter · Baxter Exactamix Em 2400+1

Published

2020-06-29

·

Updated

2020-07-08

·

CVE-2020-12016

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Baxter ExactaMix EM 2400 versions 1.10 through 1.14 Baxter ExactaMix EM 1200 versions 1.1 through 1.5
Description The issue concerns hard-coded administrative account credentials for the ExactaMix operating system. This could allow an attacker with network access to view sensitive data, including Protected Health Information (PHI), and gain unauthorized access to system resources, enabling them to execute software or view and update files, directories, or system configuration.
Recommendations For Baxter ExactaMix EM 2400 versions 1.10 through 1.14, consider disabling the administrative account until a patch is available to prevent exploitation. For Baxter ExactaMix EM 1200 versions 1.1 through 1.5, restrict access to the ExactaMix operating system to minimize the risk of unauthorized access. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12016

Affected Products

Baxter Exactamix Em1200
Baxter Exactamix Em 2400