SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12048

An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.

HIGH 7.5EPSS 0.45%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.45%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the network could observe sensitive treatment and prescription data sent between the Phoenix system and the Exalis tool.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.45% probability · 38th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
baxter/phoenix x36 firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.