CVE-2014-5434: Critical severity baxter sigma spectrum infusion system vulnerability
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to or from the WBM using this account. Baxter has released a new version of the SIGMA Spectrum Infusion System, Version 8, which incorporates hardware and software changes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-5434?
CVE-2014-5434 has a moderate severity level due to the presence of hard-coded credentials.
How do I fix CVE-2014-5434?
To remediate CVE-2014-5434, it is recommended to update to the latest firmware version provided by Baxter.
What devices are affected by CVE-2014-5434?
CVE-2014-5434 affects the Baxter SIGMA Spectrum Infusion System version 6.05 and the Wireless Battery Module version 16.
Are there any mitigations for CVE-2014-5434?
There are no effective mitigations for CVE-2014-5434 other than updating to a secure firmware version.
Can files be transferred using the default account in CVE-2014-5434?
Baxter asserts that no files can be transferred to or from the Wireless Battery Module using the default account associated with CVE-2014-5434.