Use of Hard-coded Password in PrismaFlex and PrisMax - CVE-2020-12037
Published: June 19, 2020
PrismaFlex
PrisMax
Baxter
Description
The vulnerability allows a local user to gain access to potentionaly sensitive information.
The vulnerability exists due to the affected device contains a hard-coded service password that provides access to biomedical information, device settings, calibration settings, and network configurations. An authenticated attacker with physical access can use these credentials to modify device settings and calibration.