CVE-2020-12048
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
Phoenix Hemodialysis Delivery System SW versiones 3.36 y 3.40, el dispositivo Phoenix Hemodialysis no admite el cifrado de datos en tránsito (por ejemplo, TLS/SSL) al transmitir datos de tratamiento y prescripción en la red entre el sistema Phoenix y la herramienta de gestión de datos de diálisis Exalis. Un atacante con acceso a la red podría observar el tratamiento confidencial y los datos de prescripción enviados entre el sistema Phoenix y la herramienta Exalis
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-21 CVE Reserved
- 2020-06-29 CVE Published
- 2023-03-15 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-319: Cleartext Transmission of Sensitive Information
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://www.us-cert.gov/ics/advisories/icsma-20-170-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Baxter Search vendor "Baxter" | Phoenix X36 Firmware Search vendor "Baxter" for product "Phoenix X36 Firmware" | 3.36 Search vendor "Baxter" for product "Phoenix X36 Firmware" and version "3.36" | - |
Affected
| in | Baxter Search vendor "Baxter" | Phoenix X36 Search vendor "Baxter" for product "Phoenix X36" | - | - |
Safe
|
Baxter Search vendor "Baxter" | Phoenix X36 Firmware Search vendor "Baxter" for product "Phoenix X36 Firmware" | 3.40 Search vendor "Baxter" for product "Phoenix X36 Firmware" and version "3.40" | - |
Affected
| in | Baxter Search vendor "Baxter" | Phoenix X36 Search vendor "Baxter" for product "Phoenix X36" | - | - |
Safe
|