Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsma-20-170-03 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2020-06-29 07:15
Updated : 2020-07-16 06:12
NVD link : CVE-2020-12048
Mitre link : CVE-2020-12048
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
baxter
- phoenix_x36
- phoenix_x36_firmware