Baxter Phoenix Information Leakage Vulnerability
Baxter has released details of a cleartext transmission vulnerability (CWE-319) affecting their Phoenix hemodialysis delivery system. they claim that an attacker with local network access could exploit this vulnerability to obtain patient treatment and prescription data.
Summary
Baxter has released details of a cleartext transmission vulnerability (CWE-319) affecting their Phoenix hemodialysis delivery system. they claim that an attacker with local network access could exploit this vulnerability to obtain patient treatment and prescription data.
Affected platforms
The following platforms are known to be affected:
- Baxter Phoenix Hemodialysis Delivery System - Versions 3.36 and 3.40
Threat details
The vulnerability is a result of Phoenix systems not supporting in-transit encryption of data when communicating with Baxter's Exalis dialysis data management tool. A user with with access to the same network segment may perform intercept this data or perform man-in-the-middle attacks.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Baxter has recommended the following mitigating controls be applied where possible:
For further information please review Baxter's security bulletin. |
CVE Vulnerabilities
Last edited: 29 June 2021 12:01 pm