CVE-2024-6796: Baxter Connex Health Portal

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.

Affected products

  • Baxter Connex Health Portal: before 2024-08-30 (fixed in 2024-08-30)

Published 2024-09-09. Last modified 2026-06-17.