CVE-2020-12047: Critical severity baxter sigma spectrum infusion system vulnerability
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12047?
CVE-2020-12047 is classified as a high-severity vulnerability due to the presence of hard-coded credentials in an FTP service.
How do I fix CVE-2020-12047?
To mitigate CVE-2020-12047, disable the FTP service or change the default settings and credentials if possible.
What systems are affected by CVE-2020-12047?
CVE-2020-12047 affects the Baxter Spectrum WBM versions 17, 20D29, 20D30, 20D31, and 22D24 when used with Baxter Spectrum v8.x firmware.
What risks are associated with CVE-2020-12047?
The risks associated with CVE-2020-12047 include unauthorized access to sensitive data and potential manipulation of infusion devices due to hard-coded credentials.
Is CVE-2020-12047 being actively exploited?
There have been no confirmed reports of active exploitation for CVE-2020-12047; however, the vulnerability poses a significant security risk that should be addressed.