First published: Mon Jun 29 2020(Updated: )
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Sigma Spectrum Infusion System | =8.0 | |
Baxter Sigma Spectrum Infusion System | ||
Baxter Wireless Battery Module | =17 | |
Baxter Wireless Battery Module | =20d29 | |
Baxter Wireless Battery Module | =20d30 | |
Baxter Wireless Battery Module | =20d31 | |
Baxter Wireless Battery Module | =22d24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12043 is considered a moderate severity vulnerability due to its implications on the security of the Baxter Spectrum WBM when configured for wireless networking.
To mitigate CVE-2020-12043, it is recommended to disable FTP service or reboot the device to temporarily close the service.
CVE-2020-12043 affects versions v17, v20D29, v20D30, v20D31, and v22D24 of the Baxter Spectrum WBM.
The impact of CVE-2020-12043 is that an unauthorized user may exploit the running FTP service to gain access to the device.
Yes, users should consider disabling the FTP service or regularly rebooting their devices to minimize the potential exposure from CVE-2020-12043.