Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Baxter Healthcare

First CVE: Mar 26, 2019Active for: 7 yearsTotal CVEs: 27
28.5
VTI Score
Low

Baxter Healthcare's vulnerability profile centers on a focused but high-consequence portfolio of medical infusion and delivery systems, including the Sigma Spectrum platform and wireless battery modules, that directly support patient care in clinical settings. The vendor's disclosures skew strongly toward critical-severity outcomes and concentrate consistently around credential and authentication weaknesses—hard-coded credentials, hard-coded passwords, cleartext transmission, and cleartext storage of sensitive information—that reflect the embedded firmware and networked-device nature of medical-device software. These weakness classes are particularly consequential in hospital environments where device compromise can affect patient safety and operational continuity, and they recur across both the primary infusion platforms and their supporting firmware and wireless components. Defenders and clinical engineering teams should treat Baxter infusion-system advisories as high-priority and validate network segmentation and access controls around these devices; live severity, exploitation status, and remediation requirements are shown alongside this summary.

FAUCET AI Generated
27
Total CVEs
More Total CVEs than 97% of tracked vendors
0.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 1% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Baxter Healthcare over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 26, 2019
7 years ago
Most Recent CVE
Sep 9, 2024
683 days ago

Self-Reporting Analysis

Of all the CVEs published by Baxter Healthcare as a CNA, 33.3% affect products that Baxter Healthcare develops as a vendor.

33.3%
66.7%
Self-reported: 6 (33.3%)
Third-party: 12 (66.7%)

Of all the CVEs published that affect products developed by Baxter Healthcare, 22.2% are self-published by Baxter Healthcare as a CNA.

22.2%
77.8%
Self-published: 6 (22.2%)
Other CNAs: 21 (77.8%)

Products(32 total)

Top CVEs

Signals from CVEs in this vendor scope (27 CVEs).

27 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-6795CRITICAL
In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex
Sep 9, 20249.833NONO
CVE-2020-12045CRITICAL
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when used in conjunction with a Baxter Spectrum v8.x (model 35700BAX2), operates a Telnet service on Port 1023 wit
Jun 29, 20209.831NONO
CVE-2014-5433CRITICAL
An unauthenticated remote attacker may be able to execute commands to view wireless account credentials that are stored in cleartext on Baxter SIGMA Spectrum Infusion System versio
Mar 26, 20199.831NONO
CVE-2014-5432CRITICAL
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A r
Mar 26, 20199.831NONO
CVE-2014-5434CRITICAL
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 has a default account with hard-coded credentials used with the FT
Mar 26, 20199.831NONO
CVE-2021-43935CRITICAL
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any
Dec 15, 20219.829NONO
CVE-2020-12032CRITICAL
Baxter ExactaMix EM 2400 Versions 1.10, 1.11 and ExactaMix EM1200 Versions 1.1, 1.2 systems store device data with sensitive information in an unencrypted database. This could allo
Jun 29, 20209.128NONO
CVE-2024-6796CRITICAL
In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized
Sep 9, 20249.126NONO
CVE-2020-12047CRITICAL
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24), when used with a Baxter Spectrum v8.x (model 35700BAX2) in a factory-default wireless configuration enables an FT
Jun 29, 20209.826NONO
CVE-2020-12043CRITICAL
The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) when configured for wireless networking the FTP service operating on the WBM remains operational until the WBM is
Jun 29, 20209.826NONO
View all 27 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products27 CVEs
30%
19%
48%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local1 (3.7%)
Network19 (70.4%)
Unknown0 (0.0%)
Physical6 (22.2%)
Adjacent Network1 (3.7%)
Attack Complexity
Low26 (96.3%)
High1 (3.7%)
Unknown0 (0.0%)
User Interaction
None27 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low4 (14.8%)
High0 (0.0%)
None23 (85.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (27 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Baxter Healthcare.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Baxter Healthcare — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Baxter Healthcare's Products

View all 2 CNAs →

Top CWEs