Hard-coded Password Vulnerability in Baxter SIGMA Spectrum Infusion System
CVE-2014-5431

6.8MEDIUM

Key Information:

Vendor

Baxter

Vendor
CVE Published:
26 March 2019

What is CVE-2014-5431?

The Baxter SIGMA Spectrum Infusion System version 6.05 comes with a hard-coded password that allows unauthorized access to critical biomedical information and limited device settings. If an attacker gains physical access to the infusion system, they can exploit this vulnerability to modify essential configurations, including enabling or disabling wireless connections and controlling alarm settings for infusion phases. This poses a significant risk to patient safety and device integrity. Baxter has addressed these issues in version 8 of the SIGMA Spectrum Infusion System, incorporating crucial hardware and software improvements.

Affected Version(s)

SIGMA Spectrum Infusion System 6.05 (model 35700BAX) with wireless battery module (WBM) version 16

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.