Use of Hard-coded Password in PrismaFlex and PrisMax - CVE-2020-12037
Published: June 19, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentionaly sensitive information.
The vulnerability exists due to the affected device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configurations. An authenticated attacker with physical access can use these credentials to modify device settings and calibration.
Affected software
PrisMax
How to mitigate CVE-2020-12037
PrisMax - update to 3.0