SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12020

Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

MEDIUM 6.1EPSS 0.31%

Does this matter?

Lower severity and a low EPSS score (0.31%). Track it; it rarely justifies an emergency change on its own.

Description

Baxter ExactaMix EM 2400 Versions 1.10, 1.11, and 1.13 and ExactaMix EM1200 Versions 1.1, 1.2, and 1.4 does not restrict non administrative users from gaining access to the operating system and editing the application startup script. Successful exploitation of this vulnerability may allow an attacker to alter the startup script as the limited-access user.

CVSS 3.1
6.1 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
EPSS
0.31% probability · 24th percentile
CISA KEV
Not listed
Weakness
CWE-668
Affected
baxter/em2400 firmware · baxter/em1200 firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.