PT-2020-13003 · Baxter · Baxter Prismaflex+1
Published
2020-06-29
·
Updated
2020-07-14
·
CVE-2020-12036
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Baxter PrismaFlex all versions
PrisMax versions prior to 3.x
Description
The affected devices do not implement data-in-transit encryption, such as TLS/SSL, when sending treatment data to a Patient Data Management System (PDMS) or an Electronic Medical Record (EMR) system. This allows an attacker to observe sensitive data sent from the device.
Recommendations
For Baxter PrismaFlex all versions, consider configuring the device to use data-in-transit encryption, such as TLS/SSL, when sending treatment data to a PDMS or EMR system.
For PrisMax versions prior to 3.x, update to version 3.x or later, which is expected to include the necessary encryption implementation.
As a temporary workaround, consider restricting access to the network where the devices are connected to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Baxter Prismaflex
Prismax