Baxter ExactaMix Vulnerabilties
Baxter has released details of multiple vulnerabilities affecting their ExactaMix automated compounding system. they claim that a remote unauthenticated attacker could exploit some or all of these vulnerabilities to obtain sensitive data, alter system configurations or resource, or cause a denial-of-service condition.
Summary
Baxter has released details of multiple vulnerabilities affecting their ExactaMix automated compounding system. they claim that a remote unauthenticated attacker could exploit some or all of these vulnerabilities to obtain sensitive data, alter system configurations or resource, or cause a denial-of-service condition.
Affected platforms
The following platforms are known to be affected:
- Baxter ExactaMix EM1200 - Versions 1.1, 1.2, 1.4, and 1.5
- Baxter ExactaMix EM2400 - Versions 1.10, 1.11, 1.13, and 1.14
Threat details
The vulnerabilities are the result of several unrelated faults affecting all parts of affected ExactMix device operation:
- CVE-2017-0143 - CWE-20 - ExactMix devices do not correctly validate inputs via SMBv1.
- CVE-2020-12008 - CWE-319 - ExactaMix devices use cleartext messages to communicate compounding order information.
- CVE-2020-12012 - CWE-259 - ExactaMix devices use hard-coded administrative credentials.
- CVE-2020-12016 - CWE-259 - ExactaMix devices use hard-coded administrative credentials.
- CVE-2020-12020 - CWE-668 - ExactaMix devices do not restrict non-administrative access to the underlying operating system or application startup settings.
- CVE-2020-12024 - CWE-284 - ExactaMix devices do not restrict unauthorised access to the USB interface, nor do they restrict unverified loading via USB.
- CVE-2020-12032 - CWE-311 - ExacteMix devices store sensitive data in an unencrypted database.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
Baxter recommends that organisations using ExactaMix EM1200 versions 1.10 and 1.11, or ExactaMix EM2400 versions 1.1 and 1.2 contact their relevant support service teams to obtain any necessary updates. For further information, please review Baxter's security bulletin. |
CVE Vulnerabilities
Last edited: 29 June 2021 12:01 pm