Exposure of Resource to Wrong Sphere in ExactaMix EM2400 and ExactaMix EM1200 - CVE-2020-12020

 

Exposure of Resource to Wrong Sphere in ExactaMix EM2400 and ExactaMix EM1200 - CVE-2020-12020

Published: June 19, 2020


Vulnerability identifier: #VU29173
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-12020
CWE-ID:
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
ExactaMix EM2400
ExactaMix EM1200
Software vendor:
Baxter

Description

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to the affected software does not restrict non administrative users from gaining access to the operating system and editing the application startup script. A local user can alter the startup script as the limited-access user.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links