CVE-2020-12048: High severity baxter phoenix x36 vulnerability
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-12048?
CVE-2020-12048 has been classified as a high severity vulnerability due to the lack of data-in-transit encryption.
How do I fix CVE-2020-12048?
The recommended fix for CVE-2020-12048 is to update to versions of the Phoenix Hemodialysis Delivery System software that support data encryption.
What are the consequences of CVE-2020-12048?
The consequences of CVE-2020-12048 include the potential for attackers to intercept unencrypted treatment and prescription data.
Which versions are affected by CVE-2020-12048?
CVE-2020-12048 affects Phoenix Hemodialysis Delivery System versions 3.36 and 3.40.
Who is impacted by CVE-2020-12048?
Healthcare facilities using the vulnerable versions of the Phoenix Hemodialysis system are impacted by CVE-2020-12048.