CVE-2020-12041: Baxter Sigma Spectrum Infusion System Firmware

Critical severity, CVSS 9.4. EPSS: 1.4% chance of exploitation in the next 30 days.

The Baxter Spectrum WBM (v17, v20D29, v20D30, v20D31, and v22D24) telnet Command-Line Interface, grants access to sensitive data stored on the WBM that permits temporary configuration changes to network settings of the WBM, and allows the WBM to be rebooted. Temporary configuration changes to network settings are removed upon reboot.

Affected products

  • Baxter Sigma Spectrum Infusion System Firmware: version 8.0 only

Published 2020-06-29. Last modified 2026-06-17.