PT-2020-12999 · Baxter · Baxter Exactamix Em1200+1
Published
2020-06-29
·
Updated
2021-11-04
·
CVE-2020-12032
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Baxter ExactaMix EM 2400 versions 1.10 through 1.11
Baxter ExactaMix EM1200 versions 1.1 through 1.2
Description
The systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including Protected Health Information (PHI).
Recommendations
For Baxter ExactaMix EM 2400 versions 1.10 through 1.11, update the system to encrypt the database.
For Baxter ExactaMix EM1200 versions 1.1 through 1.2, update the system to encrypt the database.
Fix
Missing Encryption of Sensitive Data
Cleartext Storage of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Baxter Exactamix Em 2400
Baxter Exactamix Em1200