CVE-2020-12037 affects Baxter PrismaFlex and PrisMax devices (all versions, or prior to 3.x for PrisMax). The vulnerability stems from the lack of data-in-transit encryption (e.g., TLS/SSL) when these devices transmit patient treatment data to PDMS or EMR systems. This allows an unauthenticated network attacker to passively observe sensitive patient data, resulting in a high severity CVSS score of 7.5. Despite the high severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:baxter:prismaflex_firmware:*:*:*:*:*:*:*:* | ||
< 3.0CPE matchmatch criteria | cpe:2.3:o:baxter:prismax_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.