Baxter Healthcare's vulnerability profile centers on a focused but high-consequence portfolio of medical infusion and delivery systems, including the Sigma Spectrum platform and wireless battery modules, that directly support patient care in clinical settings. The vendor's disclosures skew strongly toward critical-severity outcomes and concentrate consistently around credential and authentication weaknesses—hard-coded credentials, hard-coded passwords, cleartext transmission, and cleartext storage of sensitive information—that reflect the embedded firmware and networked-device nature of medical-device software. These weakness classes are particularly consequential in hospital environments where device compromise can affect patient safety and operational continuity, and they recur across both the primary infusion platforms and their supporting firmware and wireless components. Defenders and clinical engineering teams should treat Baxter infusion-system advisories as high-priority and validate network segmentation and access controls around these devices; live severity, exploitation status, and remediation requirements are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Baxter Healthcare over time
Of all the CVEs published by Baxter Healthcare as a CNA, 33.3% affect products that Baxter Healthcare develops as a vendor.
Of all the CVEs published that affect products developed by Baxter Healthcare, 22.2% are self-published by Baxter Healthcare as a CNA.
Signals from CVEs in this vendor scope (27 CVEs).
27 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-6795CRITICAL In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex | Sep 9, 2024 | 9.8 | 33 | NO | NO |
CVE-2020-12045CRITICAL The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 wit | Jun 29, 2020 | 9.8 | 31 | NO | NO |
CVE-2014-5433CRITICAL An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System versio | Mar 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-5432CRITICAL Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A r | Mar 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2014-5434CRITICAL Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FT | Mar 26, 2019 | 9.8 | 31 | NO | NO |
CVE-2021-43935CRITICAL The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any | Dec 15, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-12032CRITICAL Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allo | Jun 29, 2020 | 9.1 | 28 | NO | NO |
CVE-2024-6796CRITICAL In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized | Sep 9, 2024 | 9.1 | 26 | NO | NO |
CVE-2020-12047CRITICAL The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FT | Jun 29, 2020 | 9.8 | 26 | NO | NO |
CVE-2020-12043CRITICAL The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is | Jun 29, 2020 | 9.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (27 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Baxter Healthcare.
Media articles that mention a CVE ID that affects a product developed by Baxter Healthcare — matched by CVE ID, not by vendor name.