Lucene search

K
cve[email protected]CVE-2020-12032
HistoryJun 29, 2020 - 2:15 p.m.

CVE-2020-12032

2020-06-2914:15:11
CWE-312
CWE-311
web.nvd.nist.gov
28
cve-2020-12032
baxter exactamix em 2400
baxter exactamix em1200
unencrypted database
sensitive information
network access
phi
nvd

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.0%

Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.

Affected configurations

NVD
Node
baxterem2400_firmwareMatch1.10
OR
baxterem2400_firmwareMatch1.11
AND
baxterem2400Match-
Node
baxterem1200_firmwareMatch1.1
OR
baxterem1200_firmwareMatch1.2
AND
baxterem1200Match-

CNA Affected

[
  {
    "product": "Baxter ExactaMix EM 2400 & EM 1200",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5"
      }
    ]
  }
]

6.4 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

8.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

53.0%

Related for CVE-2020-12032