Hard-coded Service Password Vulnerability in Baxter PrismaFlex and PrisMax Devices
CVE-2020-12035

4.9MEDIUM

Key Information:

Vendor

Baxter

Vendor
CVE Published:
29 June 2020

What is CVE-2020-12035?

The Baxter PrismaFlex and PrisMax devices are impacted by a security flaw due to a hard-coded service password. This vulnerability permits unauthorized users to gain access to sensitive biomedical information, adjust device settings, and manipulate calibration settings. The presence of such a password poses significant risks, potentially allowing attackers to compromise device operations and patient safety. It is vital for users to apply security patches and evaluate their device configurations to mitigate these risks.

Affected Version(s)

Baxter PrismaFlex and PrisMax PrismaFlex all versions, PrisMax all versions prior to 3.x

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.