Hard-coded Service Password Vulnerability in Baxter PrismaFlex and PrisMax Devices
CVE-2020-12035
4.9MEDIUM
What is CVE-2020-12035?
The Baxter PrismaFlex and PrisMax devices are impacted by a security flaw due to a hard-coded service password. This vulnerability permits unauthorized users to gain access to sensitive biomedical information, adjust device settings, and manipulate calibration settings. The presence of such a password poses significant risks, potentially allowing attackers to compromise device operations and patient safety. It is vital for users to apply security patches and evaluate their device configurations to mitigate these risks.
Affected Version(s)
Baxter PrismaFlex and PrisMax PrismaFlex all versions, PrisMax all versions prior to 3.x
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved