CVE-2020-12039

LOW

Baxter Sigma Spectrum - Info Disclosure

Title source: llm
STIX 2.1

Description

Baxter Sigma Spectrum Infusion Pumps Sigma Spectrum Infusion System v's6.x model 35700BAX & Baxter Spectrum Infusion System v's8.x model 35700BAX2 contain hardcoded passwords when physically entered on the keypad provide access to biomedical menus including device settings, view calibration values, network configuration of Sigma Spectrum WBM if installed.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://www.us-cert.gov/ics/advisories/icsma-20-170-04

Scores

CVSS v3 2.4
EPSS 0.0033
EPSS Percentile 24.9%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-259 CWE-798
Status published
Products (2)
baxter/sigma_spectrum_infusion_system_firmware 8.0
baxter/sigma_spectrum_infusion_system_firmware 6.0 - 6.05
Published Jun 29, 2020
Tracked Since Feb 18, 2026