CRITICAL · 9.4

CVE-2020-12041

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to netwo...

Vulnerability Description

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.

CVSS Score

9.4

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
HIGH

Affected Products

VendorProductVersions
BaxterSigma Spectrum Infusion System Firmware8.0
BaxterSigma Spectrum Infusion System-
BaxterWireless Battery Module17

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-12041?

CVE-2020-12041 is a vulnerability with a CVSS score of 9.4 (CRITICAL). The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to netwo...

How severe is CVE-2020-12041?

CVE-2020-12041 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2020-12041?

Check the references section above for vendor advisories and patch information. Affected products include: Baxter Sigma Spectrum Infusion System Firmware, Baxter Sigma Spectrum Infusion System, Baxter Wireless Battery Module.