First published: Mon Jun 29 2020(Updated: )
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Sigma Spectrum Infusion System | =8.0 | |
Baxter Sigma Spectrum Infusion System | ||
Baxter Wireless Battery Module | =17 | |
Baxter Wireless Battery Module | =20d29 | |
Baxter Wireless Battery Module | =20d30 | |
Baxter Wireless Battery Module | =20d31 | |
Baxter Wireless Battery Module | =22d24 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12047 is classified as a high-severity vulnerability due to the presence of hard-coded credentials in an FTP service.
To mitigate CVE-2020-12047, disable the FTP service or change the default settings and credentials if possible.
CVE-2020-12047 affects the Baxter Spectrum WBM versions 17, 20D29, 20D30, 20D31, and 22D24 when used with Baxter Spectrum v8.x firmware.
The risks associated with CVE-2020-12047 include unauthorized access to sensitive data and potential manipulation of infusion devices due to hard-coded credentials.
There have been no confirmed reports of active exploitation for CVE-2020-12047; however, the vulnerability poses a significant security risk that should be addressed.