In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01
https://www.hipaajournal.com/maximum-severity-vulnerability-identified-in-baxter-connex-health-portal/
https://www.darkreading.com/ics-ot-security/cisa-flags-ics-bugs-in-baxter-mitsubishi-products
Source: Mitre, NVD
Published: 2024-09-09
Updated: 2024-09-20
Base Score: 9.4
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:N
Severity: High
Base Score: 9.1
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity: Critical
EPSS: 0.00124