PT-2020-12999 · Baxter · Baxter Exactamix Em1200+1

Published

2020-06-29

·

Updated

2021-11-04

·

CVE-2020-12032

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Baxter ExactaMix EM 2400 versions 1.10 through 1.11 Baxter ExactaMix EM1200 versions 1.1 through 1.2
Description The systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including Protected Health Information (PHI).
Recommendations For Baxter ExactaMix EM 2400 versions 1.10 through 1.11, update the system to encrypt the database. For Baxter ExactaMix EM1200 versions 1.1 through 1.2, update the system to encrypt the database.

Fix

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12032

Affected Products

Baxter Exactamix Em 2400
Baxter Exactamix Em1200