Skip to main content

Baxter ExactaMix Vulnerabilties

Baxter has released details of multiple vulnerabilities affecting their ExactaMix automated compounding system. they claim that a remote unauthenticated attacker could exploit some or all of these vulnerabilities to obtain sensitive data, alter system configurations or resource, or cause a denial-of-service condition.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Baxter has released details of multiple vulnerabilities affecting their ExactaMix automated compounding system. they claim that a remote unauthenticated attacker could exploit some or all of these vulnerabilities to obtain sensitive data, alter system configurations or resource, or cause a denial-of-service condition.


Affected platforms

The following platforms are known to be affected:

  • Baxter ExactaMix EM1200 - Versions 1.1, 1.2, 1.4, and 1.5
  • Baxter ExactaMix EM2400 - Versions 1.10, 1.11, 1.13, and 1.14

Threat details

The vulnerabilities are the result of several unrelated faults affecting all parts of affected ExactMix device operation:

  • CVE-2017-0143 - CWE-20 - ExactMix devices do not correctly validate inputs via SMBv1.
  • CVE-2020-12008 - CWE-319 - ExactaMix devices use cleartext messages to communicate compounding order information.
  • CVE-2020-12012 - CWE-259 - ExactaMix devices use hard-coded administrative credentials.
  • CVE-2020-12016 - CWE-259 - ExactaMix devices use hard-coded administrative credentials.
  • CVE-2020-12020 - CWE-668 - ExactaMix devices do not restrict non-administrative access to the underlying operating system or application startup settings.
  • CVE-2020-12024 - CWE-284 - ExactaMix devices do not restrict unauthorised access to the USB interface, nor do they restrict unverified loading via USB.
  • CVE-2020-12032 - CWE-311 - ExacteMix devices store sensitive data in an unencrypted database.

For further information:


Remediation steps

Type Step

Baxter recommends that organisations using ExactaMix EM1200 versions 1.10 and 1.11, or ExactaMix EM2400 versions 1.1 and 1.2 contact their relevant support service teams to obtain any necessary updates. For further information, please review Baxter's security bulletin.



Last edited: 29 June 2021 12:01 pm