Vulnerability Description
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Baxter | Sigma Spectrum Infusion System Firmware | 8.0 |
| Baxter | Sigma Spectrum Infusion System | - |
| Baxter | Wireless Battery Module | 17 |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsma-20-170-04Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsma-20-170-04Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2020-12041?
CVE-2020-12041 is a vulnerability with a CVSS score of 9.4 (CRITICAL). The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to netwo...
How severe is CVE-2020-12041?
CVE-2020-12041 has been rated CRITICAL with a CVSS base score of 9.4/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-12041?
Check the references section above for vendor advisories and patch information. Affected products include: Baxter Sigma Spectrum Infusion System Firmware, Baxter Sigma Spectrum Infusion System, Baxter Wireless Battery Module.