PT-2020-13007 · Baxter · Baxter Sigma Spectrum Infusion System+1

Published

2020-06-29

·

Updated

2022-03-03

·

CVE-2020-12040

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Sigma Spectrum Infusion System versions 6.x Baxter Spectrum Infusion System versions 8.x
Description The issue concerns the use of an unauthenticated clear-text communication channel at the application layer to send and receive system status and operational data. This could allow an attacker who has bypassed network security measures to view sensitive non-private data or perform a man-in-the-middle attack.
Recommendations For Sigma Spectrum Infusion System version 6.x, consider implementing secure communication protocols to encrypt data transmission. For Baxter Spectrum Infusion System version 8.x, restrict access to the system to minimize the risk of exploitation until a secure communication channel is established.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-12040

Affected Products

Baxter Sigma Spectrum Infusion System
Sigma Spectrum Infusion System