Loading HuntDB...

baxter

9 Products 20 CVEs

CVE Severity Distribution (All Time)

Critical
9
High
1
Medium
3
Low
1

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 10 CVEs

Recent CVEs

View all
CVE-2024-48967 CRITICAL 7 months, 3 weeks ago

The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic exa…

CVE-2024-48966 CRITICAL 7 months, 3 weeks ago

The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Se…

CVE-2024-48970 CRITICAL 7 months, 3 weeks ago

The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory …

CVE-2024-48974 CRITICAL 7 months, 3 weeks ago

The ventilator does not perform proper file integrity checks when adopting firmware updates. This makes it possible for an attacker to force unauthor…

CVE-2024-48973 CRITICAL 7 months, 3 weeks ago

The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug p…

CVE-2024-48971 CRITICAL 7 months, 3 weeks ago

The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obt…

CVE-2024-9832 CRITICAL 7 months, 3 weeks ago

There is no limit on the number of failed login attempts permitted with the Clinician Password or the Serial Number Clinician Password. An attacker c…

CVE-2024-9834 CRITICAL 7 months, 3 weeks ago

Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclo…

CVE-2024-6796 HIGH 9 months, 3 weeks ago

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated…

CVE-2024-6795 CRITICAL 9 months, 3 weeks ago

In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gai…