CVE-2020-12037
CVE-2020-12037
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
29 Jun 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Baxter PrismaFlex all versions, PrisMax all versions prior to 3.x, The affected devices do not implement data-in-transit encryption (e.g., TLS/SSL) when configured to send treatment data to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. An attacker could observe sensitive data sent from the device.
Affected products
n/a · Baxter PrismaFlex and PrisMaxWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →