CVE-2020-12040: Critical severity baxter sigma spectrum infusion system vulnerability
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented network security measures to view sensitive non-private data or to perform a man-in-the-middle attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12040?
CVE-2020-12040 is classified as a high severity vulnerability due to the potential for unauthenticated access to sensitive medical system data.
How do I fix CVE-2020-12040?
To mitigate CVE-2020-12040, apply the latest firmware updates provided by Baxter for the affected Spectrum Infusion Systems.
What versions of the Sigma Spectrum Infusion System are affected by CVE-2020-12040?
CVE-2020-12040 affects Sigma Spectrum Infusion System firmware versions 6.0 to 6.05 and version 8.0.
What type of communication is exploited in CVE-2020-12040?
CVE-2020-12040 exploits an unauthenticated clear-text communication channel used for sending and receiving operational data.
Can CVE-2020-12040 lead to data breaches?
Yes, CVE-2020-12040 can potentially allow attackers to intercept and manipulate sensitive system status and operational data.