Description
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
Published: 2020-06-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-4364 Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.
History

No history.

Subscriptions

Baxter Phoenix X36 Phoenix X36 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-04T11:48:57.931Z

Reserved: 2020-04-21T00:00:00.000Z

Link: CVE-2020-12048

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-06-29T14:15:11.990

Modified: 2024-11-21T04:59:10.710

Link: CVE-2020-12048

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses