CVE-2014-5431

Description

Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 contains a hard-coded password, which provides access to basic biomedical information, limited device settings, and network configuration of the WBM, if connected. The hard-coded password may allow an attacker with physical access to the device to access management functions to make unauthorized configuration changes to biomedical settings such as turn on and off wireless connections and the phase-complete audible alarm that indicates the end of an infusion phase. Baxter has released a new version of the SIGMA Spectrum Infusion System, version 8, which incorporates hardware and software changes.

Categories

6.8
CVSS
Severity: Medium
CVSS 3.0 •
CVSS 2.0 •
EPSS 0.05%
Third-Party Advisory us-cert.gov
Affected: Baxter SIGMA Spectrum Infusion System
Published at:
Updated at:

References

Link Tags
https://ics-cert.us-cert.gov/advisories/ICSA-15-181-01 us government resource third party advisory mitigation

Frequently Asked Questions

What is the severity of CVE-2014-5431?
CVE-2014-5431 has been scored as a medium severity vulnerability.
How to fix CVE-2014-5431?
To fix CVE-2014-5431, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2014-5431 being actively exploited in the wild?
As for now, there are no information to confirm that CVE-2014-5431 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2014-5431?
CVE-2014-5431 affects Baxter SIGMA Spectrum Infusion System.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.