Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published: 2020-06-29T13:51:49

Updated: 2024-08-04T11:48:57.381Z

Reserved: 2020-04-21T00:00:00

Link: CVE-2020-12020

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2020-06-29T14:15:11.210

Modified: 2020-07-08T13:48:49.293

Link: CVE-2020-12020

cve-icon Redhat

No data.