Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in all versions prior to 1.52.
The Welch Allyn Connex Spot Monitor device uses a default cryptographic key that is not unique to each installation and was not changed by the manufacturer or user. An attacker with knowledge of this key can use it to break the cryptographic protection mechanisms implemented in the device. As a result, unauthorized manipulation of the device configuration or its operating environment is possible without requiring authentication.
An attacker can remotely manipulate the configuration of the medical device and its environment, which in the context of a patient monitoring device may threaten the integrity of clinical data and patient safety.
The Welch Allyn Connex Spot Monitor device software should be updated to version 1.52 or later. Detailed instructions are available in the CISA ICS-CERT security advisory at: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-151-02
Baxter Welch Allyn Connex Spot Monitor in all software versions prior to 1.52.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X