Telnet Command-Line Interface Vulnerability in Baxter Spectrum WBM Products
CVE-2020-12041

9.4CRITICAL

Key Information:

Vendor

Baxter

Vendor
CVE Published:
29 June 2020

What is CVE-2020-12041?

The telnet Command-Line Interface on specific versions of Baxter Spectrum WBM devices allows unauthorized access to sensitive information. This vulnerability permits temporary changes to network settings and enables system reboots, which can lead to potential malicious activities and unauthorized control over the device configurations.

Affected Version(s)

Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum v6.x model 35700BAX, Baxter Spectrum v8.x model 35700BAX2,Sigma Spectrum v6.x with Wireless Battery Module v9,11,13,14,15,16,v20D29,v20D30,v20D31,v22D24, Baxter Spectrum v8.x with Wireless Battery Module v17,v20D29,v20D30,v20D31,v22D24,Baxter Spectrum Wireless Battery Module v17,v20D29,v20D30,v20D31,v22D24,Baxter Spectrum LVP v8.x w/Wireless Battery Module v17,v20D29,v20D30,v20D31,v22D24

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.