Vulnerability Details CVE-2020-12032
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allow an attacker with network access to view or modify sensitive data including PHI.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.7%
CVSS Severity
CVSS v3 Score 9.1
CVSS v2 Score 6.4
Products affected by CVE-2020-12032
-
cpe:2.3:h:baxter:em1200:-
-
cpe:2.3:h:baxter:em2400:-
-
cpe:2.3:o:baxter:em1200_firmware:1.1
-
cpe:2.3:o:baxter:em1200_firmware:1.2
-
cpe:2.3:o:baxter:em2400_firmware:1.10
-
cpe:2.3:o:baxter:em2400_firmware:1.11