First published: Mon Sep 09 2024(Updated: )
In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.
Credit: productsecurity@baxter.com
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Connex Health Portal | <2024-08-30 |
Baxter is unaware of any exploitation of this vulnerability in our product and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-6796 has a high severity rating due to its potential for unauthorized access to sensitive database information.
To fix CVE-2024-6796, update the Baxter Connex health portal to a version released after August 30, 2024.
CVE-2024-6796 can enable unauthenticated attackers to gain unauthorized access and modify content in the Connex portal's database.
Currently, there is no documented workaround for CVE-2024-6796; updating the software is recommended.
Organizations using Baxter Connex health portal versions prior to August 30, 2024, are affected by CVE-2024-6796.