Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home Alerts

Feds Warn of Flaws in Baxter Devices

June 4, 2024
Reading Time: 2 mins read
in Alerts
Feds Warn of Flaws in Baxter Devices

U.S. federal authorities have issued alerts about significant vulnerabilities in two medical devices from Baxter, a major manufacturer. The Department of Health and Human Services‘ Health Sector Cyber Coordination Center revealed that these flaws, affecting the Baxter Welch Allyn Connex Spot Monitor and the Baxter Welch Allyn Configuration Tool, could be exploited remotely, potentially compromising patient care. These vulnerabilities were highlighted in advisories from the Cybersecurity and Infrastructure Security Agency.

The first issue involves the Baxter Welch Allyn Connex Spot Monitor, which has a vulnerability due to the use of default cryptographic keys in versions 1.52 and earlier. This flaw, assigned a high severity score of 9.1, could allow attackers to alter device configurations and firmware, affecting patient care. Baxter has addressed this by releasing an update that mitigates the issue, advising users to upgrade to the latest version and apply proper security measures.

The second vulnerability pertains to the Baxter Welch Allyn Configuration Tool, which suffers from insufficiently protected credentials. This flaw, with a CVSS score of 9.4, could lead to unauthorized exposure of credentials. Baxter has announced that a new version will be released in the third quarter of 2024 to address this issue. In the meantime, Baxter recommends implementing strong network security controls and contacting technical support for configuration needs.

The broader issue highlights ongoing challenges in medical device security, with experts pointing out that many devices in use today lack sufficient security testing. The FDA’s new cybersecurity guidance focuses on premarket devices, leaving a gap for existing products. Improved regulatory scrutiny and clearer vulnerability disclosures are needed to better protect healthcare providers and patients from potential risks associated with these and other medical devices.

Reference:

  • Baxter Medical Devices Face Major Cybersecurity Risks
Tags: Cyber AlertsCyber Alerts 2024Cyber threatsDepartment of Health and Human Servicesfederal authoritiesJune 2024USAVulnerabilities
ADVERTISEMENT

Related Posts

Chrome Extensions Leak Data And API Keys

Chrome Extensions Leak Data And API Keys

June 6, 2025
Chrome Extensions Leak Data And API Keys

AMOS Stealer Hits macOS Via Fake CAPTCHA

June 6, 2025
Chrome Extensions Leak Data And API Keys

BADBOX Turns 1M+ IoT Devices Into Proxies

June 6, 2025
UNC6040 Vishing Group Target Salesforce Data

UNC6040 Vishing Group Target Salesforce Data

June 5, 2025
New Chaos RAT Variant Hits Windows and Linux

New Chaos RAT Variant Hits Windows and Linux

June 5, 2025
New Chaos RAT Variant Hits Windows and Linux

FBI Warns Hedera NFT Airdrop Crypto Scam

June 5, 2025

Latest Alerts

AMOS Stealer Hits macOS Via Fake CAPTCHA

Chrome Extensions Leak Data And API Keys

BADBOX Turns 1M+ IoT Devices Into Proxies

FBI Warns Hedera NFT Airdrop Crypto Scam

New Chaos RAT Variant Hits Windows and Linux

UNC6040 Vishing Group Target Salesforce Data

Subscribe to our newsletter

    Latest Incidents

    German Dog Rescue IG Hacked For Ransom

    Hack Attempt Hits German Police Phone System

    InfoJobs Spain Hit By Credential Stuffing

    KiranaPro Startup Hacked All Data Wiped

    Nervos Bridge Paused After $3.9 Million Hack

    Ukraine GUR Claims Tupolev Data Theft Hack

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial