|
209871
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12047
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209872
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded creden…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12045
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209873
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.
|
CWE-672
Operation on a Resource after Expiration or Release
|
CVE-2020-12043
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209874
|
9.4 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to netw…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2020-12041
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209875
|
9.8 |
CRITICAL
Network
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication c…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12040
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209876
|
2.4 |
LOW
Physics
|
baxter
|
sigma_spectrum_infusion_system_firmware
|
Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered …
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12039
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209877
|
7.5 |
HIGH
Network
|
baxter
|
prismaflex_firmware prismax_firmware
|
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (P…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12037
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209878
|
7.5 |
HIGH
Network
|
baxter
|
prismaflex_firmware prismax_firmware
|
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (P…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2020-12036
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209879
|
4.9 |
MEDIUM
Physics
|
baxter
|
prismaflex_firmware prismax_firmware
|
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The PrismaFlex device contains a hard-coded service password that provides access to biomedical information, device settings, calibr…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2020-12035
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209880
|
9.1 |
CRITICAL
Network
|
baxter
|
em2400_firmware em1200_firmware
|
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2020-12032
|
2024-11-21 13:59 |
2020-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|