CVE-2020-12032: Critical severity baxter em2400 vulnerability
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12032?
CVE-2020-12032 is considered a critical vulnerability due to its potential impact on sensitive patient health information.
How do I fix CVE-2020-12032?
To remediate CVE-2020-12032, users should upgrade to the latest firmware versions provided by Baxter for the ExactaMix EM2400 and EM1200 systems.
What types of data are affected by CVE-2020-12032?
CVE-2020-12032 affects sensitive data stored in an unencrypted database, including protected health information (PHI).
Who is affected by CVE-2020-12032?
Healthcare organizations using Baxter ExactaMix EM 2400 and 1200 systems with the specified firmware versions are affected by CVE-2020-12032.
Can an attacker exploit CVE-2020-12032 remotely?
Yes, an attacker with network access can view or modify sensitive data due to CVE-2020-12032.