Vulnerability Details CVE-2020-12008
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order information with an order entry system. This could allow an attacker with network access to view sensitive data including PHI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 31.3%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-12008
-
cpe:2.3:h:baxter:em1200:-
-
cpe:2.3:h:baxter:em2400:-
-
cpe:2.3:o:baxter:em1200_firmware:1.1
-
cpe:2.3:o:baxter:em1200_firmware:1.2
-
cpe:2.3:o:baxter:em2400_firmware:1.10
-
cpe:2.3:o:baxter:em2400_firmware:1.11