CVE-2020-12040: Baxter Sigma Spectrum Infusion System Firmware
Critical severity, CVSS 9.8. EPSS: 0.9% chance of exploitation in the next 30 days.
Sigma Spectrum Infusion System v's6.x (model 35700BAX) and Baxter Spectrum Infusion System Version(s) 8.x (model 35700BAX2) at the application layer uses an unauthenticated clear-text communication channel to send and receive system status and operational data. This could allow an attacker that has circumvented network security measures to view sensitive non-private data or to perform a man-in-the-middle attack.
Affected products
- Baxter Sigma Spectrum Infusion System Firmware: from 6.0, up to and including 6.05; version 8.0 only
Published 2020-06-29. Last modified 2026-06-17.