PT-2020-13007 · Baxter · Baxter Sigma Spectrum Infusion System+1
Published
2020-06-29
·
Updated
2022-03-03
·
CVE-2020-12040
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Sigma Spectrum Infusion System versions 6.x
Baxter Spectrum Infusion System versions 8.x
Description
The issue concerns the use of an unauthenticated clear-text communication channel at the application layer to send and receive system status and operational data. This could allow an attacker who has bypassed network security measures to view sensitive non-private data or perform a man-in-the-middle attack.
Recommendations
For Sigma Spectrum Infusion System version 6.x, consider implementing secure communication protocols to encrypt data transmission.
For Baxter Spectrum Infusion System version 8.x, restrict access to the system to minimize the risk of exploitation until a secure communication channel is established.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Baxter Sigma Spectrum Infusion System
Sigma Spectrum Infusion System