Command Execution Vulnerability in Baxter SIGMA Spectrum Infusion System
CVE-2014-5433

9.8CRITICAL

Key Information:

Vendor

Baxter

Vendor
CVE Published:
26 March 2019

What is CVE-2014-5433?

An unauthenticated remote attacker could exploit a vulnerability present in the Baxter SIGMA Spectrum Infusion System version 6.05 to execute arbitrary commands. This exploitation could potentially enable the attacker to view sensitive wireless account credentials stored in cleartext. As a result, unauthorized access to the host network may be obtained. To mitigate this risk, Baxter has addressed the issue in version 8 of the SIGMA Spectrum Infusion System, which includes essential hardware and software modifications.

Affected Version(s)

SIGMA Spectrum Infusion System 6.05 (model 35700BAX) with wireless battery module (WBM) version 16

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.