Baxter Healthcare

First CVE: Sep 9, 2022Active for: 4 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
8.4
Avg CVSS Score
Higher Avg CVSS Score than 93% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Baxter Healthcare as a CNA, 33.3% affect products that Baxter Healthcare develops as a vendor.

33.3%
66.7%
Self-reported: 6Third-party: 12

Of all the CVEs published that affect products developed by Baxter Healthcare, 22.2% are self-published by Baxter Healthcare as a CNA.

22.2%
77.8%
Self-published: 6Published by other CNAs: 21

Trends Over Time

The number and severity of CVEs published by Baxter Healthcare over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 9, 2022
3 years ago
Most Recent CVE
Feb 7, 2025
532 days ago

Top CVEs

All CVEs published by Baxter Healthcare as a CNA, regardless of affected vendor or product.

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex
Sep 9, 20249.833NONO
The ventilator and the Service PC lack sufficient audit logging capabilities to allow for detection of malicious activity and subsequent forensic examination. An attacker with acce
Nov 14, 202410.030NONO
The software tools used by service personnel to test & calibrate the ventilator do not support user authentication. An attacker with access to the Service PC where the tools are in
Nov 14, 202410.030NONO
The Clinician Password and Serial Number Clinician Password are hard-coded into the ventilator in plaintext form. This could allow an attacker to obtain the password off the ventil
Nov 14, 20249.328NONO
The ventilator's microcontroller lacks memory protection. An attacker could connect to the internal JTAG interface and read or write to flash memory using an off-the-shelf debuggin
Nov 14, 20249.328NONO
In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized
Sep 9, 20249.126NONO
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configu
May 31, 20249.426NONO
Use of Default Cryptographic Key vulnerability in Baxter Welch Allyn Connex Spot Monitor may allow Configuration/Environment Manipulation.This issue affects Welch Allyn Connex Spot
May 31, 20249.126NONO
The debug port on the ventilator's serial interface is enabled by default. This could allow an attacker to send and receive messages over the debug port (which are unencrypted; see
Nov 14, 20249.325NONO
Improper data protection on the ventilator's serial interface could allow an attacker to send and receive messages that result in unauthorized disclosure of information and/or have
Nov 14, 20249.325NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA18 CVEs
Severity distribution among all CVEs352,231 CVEs
MediumHighCritical
Attack Vector
Local6 (33.3%)
Network9 (50.0%)
Unknown0 (0.0%)
Physical2 (11.1%)
Adjacent Network1 (5.6%)
Attack Complexity
Low15 (83.3%)
High3 (16.7%)
Unknown0 (0.0%)
User Interaction
None17 (94.4%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (16.7%)
High0 (0.0%)
None15 (83.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Baxter Healthcare as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Baxter Healthcare as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs