CVE-2020-12047

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FTP service with hard-coded credentials.
References
Link Resource
https://www.us-cert.gov/ics/advisories/icsma-20-170-04 Third Party Advisory US Government Resource
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:baxter:sigma_spectrum_infusion_system_firmware:8.0:*:*:*:*:*:*:*
OR cpe:2.3:h:baxter:sigma_spectrum_infusion_system:-:*:*:*:*:*:*:*
cpe:2.3:h:baxter:wireless_battery_module:17:*:*:*:*:*:*:*
cpe:2.3:h:baxter:wireless_battery_module:20d29:*:*:*:*:*:*:*
cpe:2.3:h:baxter:wireless_battery_module:20d30:*:*:*:*:*:*:*
cpe:2.3:h:baxter:wireless_battery_module:20d31:*:*:*:*:*:*:*
cpe:2.3:h:baxter:wireless_battery_module:22d24:*:*:*:*:*:*:*

Information

Published : 2020-06-29 07:15

Updated : 2020-07-08 08:08


NVD link : CVE-2020-12047

Mitre link : CVE-2020-12047


JSON object : View

CWE
CWE-798

Use of Hard-coded Credentials

Advertisement

dedicated server usa

Products Affected

baxter

  • wireless_battery_module
  • sigma_spectrum_infusion_system
  • sigma_spectrum_infusion_system_firmware