First published: Mon Jun 29 2020(Updated: )
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter EM2400 | =1.10 | |
Baxter EM2400 | =1.11 | |
Baxter | ||
Baxter Em1200 | =1.1 | |
Baxter Em1200 | =1.2 | |
Baxter Em1200 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12008 is considered a high severity vulnerability due to the potential exposure of sensitive data.
To mitigate CVE-2020-12008, users should upgrade to the latest firmware versions provided by Baxter for the ExactaMix EM 2400 and EM 1200 systems.
CVE-2020-12008 can expose sensitive data including protected health information (PHI) due to cleartext communication.
Systems running Baxter ExactaMix EM 2400 firmware versions 1.10 or 1.11, or ExactaMix EM 1200 firmware versions 1.1 or 1.2 are affected by CVE-2020-12008.
If unable to update, ensure proper network segmentation and access controls are in place to limit access to vulnerable systems related to CVE-2020-12008.