9.4

CVE-2020-12041

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Baxter ≫ Sigma Spectrum Infusion System Firmware Version 8.0
   Baxter ≫ Sigma Spectrum Infusion System Version -
   Baxter ≫ Wireless Battery Module Version 17
   Baxter ≫ Wireless Battery Module Version 20d29
   Baxter ≫ Wireless Battery Module Version 20d30
   Baxter ≫ Wireless Battery Module Version 20d31
   Baxter ≫ Wireless Battery Module Version 22d24
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.4% 0.688
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.4 3.9 5.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-732 Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

https://www.us-cert.gov/ics/advisories/icsma-20-170-04
Third Party Advisory
US Government Resource