CRITICAL🇵🇱 Wersja polska

CVE-2020-12041

CVSS 9.4v3.1pub. 2020-06-29upd. 2024-11-21

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
  • Baxter Sigma Spectrum Infusion System

    HW
    Baxter
    all versions
  • Baxter Sigma Spectrum Infusion System Firmware

    OS
    Baxter
    8.0
  • Baxter Wireless Battery Module

    HW
    Baxter
    1720d2920d3020d3122d24
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-12047CRITICAL9.8PL ✓same product

Baxter Spectrum WBM — zakodowane na stałe dane logowania w usłudze FTP

CVE-2020-12040CRITICAL9.8PL ✓same product

Baxter Sigma Spectrum — nieszyfrowana komunikacja w systemie infuzji

CVE-2020-12043CRITICAL9.8PL ✓same product

Baxter Spectrum WBM — niewyłączona usługa FTP po konfiguracji sieci bezprzewodowej

CVE-2020-12045CRITICAL9.8PL ✓same product

Baxter Spectrum WBM — usługa Telnet z zakodowanymi na stałe danymi uwierzytelniającymi

CVE-2014-5434CRITICAL9.8PL ✓same product

Domyślne konto z zakodowanymi danymi logowania w Baxter SIGMA Spectrum