CVE-2014-5431
Last modified
CVE-2014-5431 is a vulnerability of currently unknown severity. Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected. The hard-coded password may allow an attacker with physical access to the device to access management functions to make unauthorized configuration changes to biomedical settings such as turn on and off wireless connections and the phase-complete audible alarm that indicates the end of an infusion phase. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected. The hard-coded password may allow an attacker with physical access to the device to access management functions to make unauthorized configuration changes to biomedical settings such as turn on and off wireless connections and the phase-complete audible alarm that indicates the end of an infusion phase. Baxter has released a new version of the SIGMA Spectrum Infusion System, version 8, which incorporates hardware and software changes.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Baxter | Sigma Spectrum Infusion System Firmware | 6.05 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-181-01Mitigation, Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-181-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-5431?
How severe is CVE-2014-5431?
How do I fix CVE-2014-5431?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2014
- CVE-2014-5425IOServer before Beta2112.exe allows remote attackers to caus…
- CVE-2014-5426MatrikonOPC OPC Server for DNP3 1.2.3 and earlier allows rem…
- CVE-2014-5427Johnson Controls Metasys 4.1 through 6.5, as used in Applica…
- CVE-2014-5428Unrestricted file upload vulnerability in unspecified web se…
- CVE-2014-5429DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 buil…
- CVE-2014-5430Untrusted search path vulnerability in ABB RobotStudio 5.6x …
- CVE-2014-5432Baxter SIGMA Spectrum Infusion System version 6.05 (model 35…
- CVE-2014-54321Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2014-5433An unauthenticated remote attacker may be able to execute co…
- CVE-2014-5434Baxter SIGMA Spectrum Infusion System version 6.05 (model 35…
- CVE-2014-5435An arbitrary memory write vulnerability exists in the dual_o…
- CVE-2014-5436A directory traversal vulnerability exists in the confd.exe …
Are you affected by CVE-2014-5431?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
