FTP Vulnerability in Baxter SIGMA Spectrum Infusion System with Wireless Battery Module
CVE-2014-5434

9.8CRITICAL

Key Information:

Vendor

Baxter

Vendor
CVE Published:
26 March 2019

What is CVE-2014-5434?

The Baxter SIGMA Spectrum Infusion System version 6.05 and Wireless Battery Module version 16 are susceptible to a vulnerability due to the presence of a default account with hard-coded credentials for the FTP protocol. Although Baxter claims that the account does not allow file transfers either to or from the Wireless Battery Module, this security flaw could potentially be exploited in other ways. To address this issue, Baxter has released version 8 of the SIGMA Spectrum Infusion System, which includes significant hardware and software enhancements aimed at mitigating these concerns.

Affected Version(s)

SIGMA Spectrum Infusion System 6.05 (model 35700BAX) with wireless battery module (WBM) version 16

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.