Baxter records
37 published records for vendor baxter.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 5.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-259 Use of Hard-coded Password8
- CWE-319 Cleartext Transmission of Sensitive Information5
- CWE-284 Improper Access Control2
- CWE-306 Missing Authentication for Critical Function2
- CWE-311 Missing Encryption of Sensitive Data2
- CWE-134 Use of Externally-Controlled Format String2
The weakness classes this vendor ships most often: where to look.
CWEAll records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2014-5432No exploit | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible viabaxter · sigma spectrum infusion system firmware · CWE-592 | Critical9.8 | — | 2.6% | Mar 26, 2019 |
40Plan | CVE-2020-12043No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the Wbaxter · sigma spectrum infusion system firmware · CWE-672 | Critical9.8 | — | 2.1% | Jun 29, 2020 |
40Plan | CVE-2014-5433No exploit | An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxtbaxter · sigma spectrum infusion system firmware · CWE-312 | Critical9.8 | — | 2.1% | Mar 26, 2019 |
40Plan | CVE-2020-12016No exploit | Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,baxter · em2400 firmware · CWE-259 | Critical9.8 | — | 1.9% | Jun 29, 2020 |
40Plan | CVE-2020-12047No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defabaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.7% | Jun 29, 2020 |
40Plan | CVE-2020-12045No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), opbaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.7% | Jun 29, 2020 |
40Plan | CVE-2024-48966No exploit | Life2000 service tools for test and calibration do not support user authenticationbaxter · life2000 ventilation system · CWE-306 | Critical10.0 | — | 0.7% | Nov 14, 2024 |
40Plan | CVE-2024-48967No exploit | Life2000 ventilator and Service PC lack sufficient audit logging capabilitiesbaxter · life2000 ventilation system · CWE-778 | Critical10.0 | — | 0.6% | Nov 14, 2024 |
39Monitor | CVE-2014-5434No exploit | Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account withbaxter · sigma spectrum infusion system firmware · CWE-259 | Critical9.8 | — | 1.6% | Mar 26, 2019 |
39Monitor | CVE-2021-43935No exploit | ICSMA-21-343-01 Hillrom Welch Allyn Cardio Productsbaxter · welch allyn connex cardio · CWE-288 | Critical9.8 | — | 1.1% | Dec 15, 2021 |
39Monitor | CVE-2020-12040No exploit | Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicatibaxter · sigma spectrum infusion system firmware · CWE-319 | Critical9.8 | — | 0.9% | Jun 29, 2020 |
39Monitor | CVE-2024-6795No exploit | Vulnerability in Baxter Connex Health Portalbaxter · connex health portal · CWE-89 | Critical9.8 | — | 0.6% | Sep 9, 2024 |
37Monitor | CVE-2020-12041No exploit | The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on tbaxter · sigma spectrum infusion system firmware · CWE-732 | Critical9.4 | — | 1.4% | Jun 29, 2020 |
37Monitor | CVE-2024-5176No exploit | Vulnerability in Welch Allyn Configuration Tool Softwarebaxter · welch allyn configuration tool · CWE-522 | Critical9.4 | — | 0.5% | May 31, 2024 |
37Monitor | CVE-2024-48973No exploit | Debug port on Life2000 Ventilator serial interface is enabled by defaultbaxter · life2000 ventilation system · CWE-1263 | Critical9.3 | — | 0.2% | Nov 14, 2024 |
37Monitor | CVE-2024-48971No exploit | Clinician Password and Serial Number Clinician Password are hard-coded in Life2000 Ventilatorbaxter · life2000 ventilation system · CWE-798 | Critical9.3 | — | 0.2% | Nov 14, 2024 |
37Monitor | CVE-2024-48970No exploit | Life2000 Ventilator microcontroller lacks memory protectionbaxter · life2000 ventilation system · CWE-1191 | Critical9.3 | — | 0.2% | Nov 14, 2024 |
37Monitor | CVE-2024-9832No exploit | No limit on failed login attempts with Clinician Password or Serial Number Clinician Password on Life2000 Ventilatorbaxter · life2000 ventilation system · CWE-307 | Critical9.3 | — | 0.2% | Nov 14, 2024 |
37Monitor | CVE-2024-48974No exploit | Life2000 Ventilator does not perform proper file integrity checks when adopting firmware updatesbaxter · life2000 ventilation system · CWE-494 | Critical9.3 | — | 0.2% | Nov 14, 2024 |
37Monitor | CVE-2024-9834No exploit | Improper data protection on Life2000 ventilator serial interfacebaxter · life2000 ventilation system · CWE-319 | Critical9.3 | — | 0.1% | Nov 14, 2024 |
36Monitor | CVE-2020-12032No exploit | Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in baxter · em2400 firmware · CWE-311 | Critical9.1 | — | 0.9% | Jun 29, 2020 |
36Monitor | CVE-2024-6796No exploit | Vulnerability in Baxter Connex Health Portalbaxter · connex health portal · CWE-284 | Critical9.1 | — | 0.4% | Sep 9, 2024 |
36Monitor | CVE-2024-1275No exploit | Vulnerability in Baxter Welch Allyn Connex Spot Monitorbaxter · welch allyn connex spot monitor · CWE-1394 | Critical9.1 | — | 0.4% | May 31, 2024 |
32Monitor | CVE-2022-26393No exploit | Format String vulnerabilitybaxter · spectrum wireless battery module firmware · CWE-134 | High8.1 | — | 0.7% | Sep 9, 2022 |
30Monitor | CVE-2020-12008No exploit | Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order infobaxter · em2400 firmware · CWE-319 | High7.5 | — | 0.9% | Jun 29, 2020 |
- CVE-2014-543240Plan
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via
CriticalCVSS 9.8No exploitEPSS 3%baxter · sigma spectrum infusion system firmwareMar 26, 2019
- CVE-2020-1204340Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the W
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2014-543340Plan
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxt
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareMar 26, 2019
- CVE-2020-1201640Plan
Baxter ExactaMix EM 2400 & EM 1200, Versions ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5,
CriticalCVSS 9.8No exploitEPSS 2%baxter · em2400 firmwareJun 29, 2020
- CVE-2020-1204740Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-defa
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2020-1204540Plan
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), op
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2024-4896640Plan
Life2000 service tools for test and calibration do not support user authentication
CriticalCVSS 10.0No exploitEPSS 1%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-4896740Plan
Life2000 ventilator and Service PC lack sufficient audit logging capabilities
CriticalCVSS 10.0No exploitEPSS 1%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2014-543439Monitor
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with
CriticalCVSS 9.8No exploitEPSS 2%baxter · sigma spectrum infusion system firmwareMar 26, 2019
- CVE-2021-4393539Monitor
ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products
CriticalCVSS 9.8No exploitEPSS 1%baxter · welch allyn connex cardioDec 15, 2021
- CVE-2020-1204039Monitor
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the applicati
CriticalCVSS 9.8No exploitEPSS 1%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2024-679539Monitor
Vulnerability in Baxter Connex Health Portal
CriticalCVSS 9.8No exploitEPSS 1%baxter · connex health portalSep 9, 2024
- CVE-2020-1204137Monitor
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on t
CriticalCVSS 9.4No exploitEPSS 1%baxter · sigma spectrum infusion system firmwareJun 29, 2020
- CVE-2024-517637Monitor
Vulnerability in Welch Allyn Configuration Tool Software
CriticalCVSS 9.4No exploitEPSS 0%baxter · welch allyn configuration toolMay 31, 2024
- CVE-2024-4897337Monitor
Debug port on Life2000 Ventilator serial interface is enabled by default
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-4897137Monitor
Clinician Password and Serial Number Clinician Password are hard-coded in Life2000 Ventilator
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-4897037Monitor
Life2000 Ventilator microcontroller lacks memory protection
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-983237Monitor
No limit on failed login attempts with Clinician Password or Serial Number Clinician Password on Life2000 Ventilator
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-4897437Monitor
Life2000 Ventilator does not perform proper file integrity checks when adopting firmware updates
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2024-983437Monitor
Improper data protection on Life2000 ventilator serial interface
CriticalCVSS 9.3No exploitEPSS 0%baxter · life2000 ventilation systemNov 14, 2024
- CVE-2020-1203236Monitor
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in
CriticalCVSS 9.1No exploitEPSS 1%baxter · em2400 firmwareJun 29, 2020
- CVE-2024-679636Monitor
Vulnerability in Baxter Connex Health Portal
CriticalCVSS 9.1No exploitEPSS 0%baxter · connex health portalSep 9, 2024
- CVE-2024-127536Monitor
Vulnerability in Baxter Welch Allyn Connex Spot Monitor
CriticalCVSS 9.1No exploitEPSS 0%baxter · welch allyn connex spot monitorMay 31, 2024
- CVE-2022-2639332Monitor
Format String vulnerability
HighCVSS 8.1No exploitEPSS 1%baxter · spectrum wireless battery module firmwareSep 9, 2022
- CVE-2020-1200830Monitor
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems use cleartext messages to communicate order info
HighCVSS 7.5No exploitEPSS 1%baxter · em2400 firmwareJun 29, 2020