Cleartext transmission of sensitive information in PrismaFlex and PrisMax - CVE-2020-12036
Published: June 19, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to software uses insecure communication channel to transmit sensitive information to a PDMS (Patient Data Management System) or an EMR (Electronic Medical Record) system. A remote attacker can gain access to sensitive data, such as treatment data.
Affected software
PrisMax
How to mitigate CVE-2020-12036
PrisMax - update to 3.0