Data Transmission Vulnerability in Phoenix Hemodialysis Delivery System by Baxter
CVE-2020-12048
7.5HIGH
What is CVE-2020-12048?
The Phoenix Hemodialysis Delivery System versions 3.36 and 3.40 are susceptible to a significant vulnerability where treatment and prescription data is transmitted over the network without encryption. As a result, any attacker with access to the same network can intercept sensitive information exchanged between the Phoenix system and the Exalis dialysis data management tool. This lack of encryption can lead to the exposure of confidential data, posing serious risks to patient privacy and compliance with data protection regulations.
Affected Version(s)
Baxter Phoenix Hemodialysis Delivery System Phoenix Hemodialysis Delivery System SW 3.36 and 3.40
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved