VYPR
Vendor

Baxter

Products
27
CVEs
30
Across products
87
Status
Private

Products

27

Recent CVEs

30
View all 30 CVEs →
  • CVE-2024-6795CriSep 9, 2024
    risk 0.65cvss 10.0epss 0.01

    In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that…

  • CVE-2020-12047CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.

  • CVE-2020-12045CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 with hard-coded credentials.

  • CVE-2020-12043CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is rebooted.

  • CVE-2020-12040CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.01

    Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow…

  • CVE-2020-12016CriJun 29, 2020
    risk 0.64cvss 9.8epss 0.02

    Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5, Baxter ExactaMix EM 2400 Versions 1.10, 1.11, 1.13, 1.14 and ExactaMix EM1200 Versions 1.1, 1.2, 1.4 and 1.5 have hard-coded…

  • CVE-2014-5433CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.02

    An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16, which may allow an attacker…

  • CVE-2014-5432CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unauthorized configuration changes to the WBM, as well as issue…

  • CVE-2014-5434CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.02

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FTP protocol. Baxter asserts no files can be transferred to or from the WBM using this account.…

  • CVE-2024-5176CriMay 31, 2024
    risk 0.61cvss epss 0.00

    Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.

  • CVE-2020-12041CriJun 29, 2020
    risk 0.61cvss 9.4epss 0.01

    The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary…

  • CVE-2024-1275CriMay 31, 2024
    risk 0.59cvss epss 0.00

    Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot Monitor in all versions prior to 1.52.

  • CVE-2020-12032CriJun 29, 2020
    risk 0.59cvss 9.1epss 0.01

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.

  • CVE-2024-6796HigSep 9, 2024
    risk 0.53cvss 8.2epss 0.00

    In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

  • CVE-2021-43935HigDec 15, 2021
    risk 0.53cvss 8.1epss 0.01

    The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password,…

  • CVE-2020-12048HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.00

    Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management…

  • CVE-2020-12037HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.00

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An…

  • CVE-2020-12036HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An…

  • CVE-2020-12008HigJun 29, 2020
    risk 0.49cvss 7.5epss 0.01

    Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.

  • CVE-2014-5431MedMar 26, 2019
    risk 0.44cvss 6.8epss 0.00

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected.…