Skip to main content

Baxter Phoenix Information Leakage Vulnerability

Baxter has released details of a cleartext transmission vulnerability (CWE-319) affecting their Phoenix hemodialysis delivery system. they claim that an attacker with local network access could exploit this vulnerability to obtain patient treatment and prescription data.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Baxter has released details of a cleartext transmission vulnerability (CWE-319) affecting their Phoenix hemodialysis delivery system. they claim that an attacker with local network access could exploit this vulnerability to obtain patient treatment and prescription data.


Affected platforms

The following platforms are known to be affected:

  • Baxter Phoenix Hemodialysis Delivery System - Versions 3.36 and 3.40

Threat details

The vulnerability is a result of Phoenix systems not supporting in-transit encryption of data when communicating with Baxter's Exalis dialysis data management tool. A user with with access to the same network segment may perform intercept this data or perform man-in-the-middle attacks.

For further information:


Remediation steps

Type Step

Baxter has recommended the following mitigating controls be applied where possible:

  • Ensure Phoenix and Exalis Server devices reside on a dedicated subnetwork.
  • Apply suitable network authentication to this subnetwork.

For further information please review Baxter's security bulletin.



CVE Vulnerabilities

Last edited: 29 June 2021 12:01 pm