CVE-2020-12020 PUBLISHED CVSS 6.099999904632568 MEDIUM

Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

EPSS 0.05% · 17.1th percentile

Risk Scores

CVSS v3.1
6.099999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
EPSS Score
0.05%
17.1th percentile

Affected Products

VendorProductVersions
baxterem2400_firmware1.11, 1.10, 1.13
n/aBaxter ExactaMix EM 2400 & EM 1200ExactaMix EM2400 Versions 1.10, 1.11, 1.13, 1.14, ExactaMix EM1200 Versions 1.1, 1.2, 1.4, 1.5
baxterem1200_firmware1.2, 1.4, 1.1

Timeline

References

Open in Interactive Console →