Remote Authentication Flaw in Baxter SIGMA Spectrum Infusion System Wireless Module
CVE-2014-5432

9.8CRITICAL

Key Information:

Vendor

Baxter

Vendor
CVE Published:
26 March 2019

What is CVE-2014-5432?

The Baxter SIGMA Spectrum Infusion System version 6.05 with specific wireless battery module versions is susceptible to a remote access vulnerability through unauthorized SSH access. This flaw enables attackers to make unauthorized configuration changes to the wireless battery module, potentially leading to compromised account credentials and shared keys. Despite Baxter's assurance that control over the infusion pump itself is not possible via the wireless module, this vulnerability poses a significant risk to device integrity and patient safety. Baxter has addressed this issue in the latest version, 8, which features essential updates in both hardware and software to enhance security.

Affected Version(s)

SIGMA Spectrum Infusion System 6.05 (model 35700BAX) with wireless battery module (WBM) version 16.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.