CVE-2020-12016 Information

Description

Baxter ExactaMix EM 2400 & EM 1200 Versions ExactaMix EM2400 Versions 1.10 1.11 1.13 1.14 ExactaMix EM1200 Versions 1.1 1.2 1.4 1.5 Baxter ExactaMix EM 2400 Versions 1.10 1.11 1.13 1.14 and ExactaMix EM1200 Versions 1.1 1.2 1.4 and 1.5 have hard-coded administrative account credentials for the ExactaMix operating system. Successful exploitation of this vulnerability may allow an attacker who has gained unauthorized access to system resources including access to execute software or to view/update files directories or system configuration. This could allow an attacker with network access to view sensitive data including PHI.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Reference

https://www.us-cert.gov/ics/advisories/icsma-20-170-01

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

9.8

Share on: