CVE-2014-5432
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unauthorized configuration changes to the WBM, as well as issue commands to access account credentials and shared keys. Baxter asserts that this vulnerability only allows access to features and functionality on the WBM and that the SIGMA Spectrum infusion pump cannot be controlled from the WBM. Baxter has released a new version of the SIGMA Spectrum Infusion System, Version 8, which incorporates hardware and software changes.
Scoring
- CVSS base score
- 0.02
- EPSS probability
- 0.59%
- CWE
- CWE-592
- Published
- 2019-03-26
- Last modified
- 2026-03-15
Affected products
- Baxter SIGMA Spectrum Infusion System
Weakness type
Related vulnerabilities
- CVE-2026-43512 — Apache Tomcat: Digest authenticator will authenticate any unknown user
- CVE-2023-30971 — Gaia unauthenticated endpoints
- CVE-2019-14843 — A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests...
- CVE-2019-14910 — A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation...
- CVE-2019-14909 — A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP...
- CVE-2019-10201 — It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message...
- CVE-2019-10198 — An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously,...
- CVE-2019-3899 — It was found that default configuration of Heketi does not require any authentication potentially...