• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer

MassDevice

The Medical Device Business Journal — Medical Device News & Articles | MassDevice

  • Special Reports
  • Technologies
    • Artificial Intelligence (AI)
    • Cardiovascular
    • Orthopedics
    • Neurological
    • Diabetes
    • Surgical Robotics
  • Business & Finance
    • Wall Street Beat
    • Earnings Reports
    • Funding Roundup
    • Mergers & Acquisitions
    • Initial Public Offering (IPO)
    • Legal News
    • Personnel Moves
    • Medtech 100 Stock Index
  • Regulatory
    • Food & Drug Administration (FDA)
    • Recalls
    • 510(k)
    • Pre-Market Approval (PMA)
    • MDSAP
    • Clinical Trials
  • Resources
    • About MassDevice
    • Leadership in Medtech
    • Manufacturers & Suppliers Search
    • MedTech100 Index
    • Videos
    • Webinars
    • Whitepapers
    • Voices
    • In-Depth Coverage
    • Latest News
  • Attend DeviceTalks
    • Events
      • DeviceTalks Minnesota – May 4
      • DeviceTalks Boston – May 27–28
      • DeviceTalks West
      • DeviceTalks Tuesdays
    • DeviceTalks Podcast Network
      • DeviceTalks Weekly
      • AbbottTalks
      • Boston ScientificTalks
      • DeviceTalks AI
      • IntuitiveTalks
      • MedtechWOMEN Talks
      • MedtronicTalks
      • Neuro Innovation Talks
      • Ortho Innovation Talks
      • Structural Heart Talks
      • StrykerTalks
  • Advertise
  • Subscribe
Home » Baxter systems flagged for cybersecurity vulnerabilities

Baxter systems flagged for cybersecurity vulnerabilities

June 19, 2020 By Sean Whooley

BaxterThe U.S. Department of Homeland Security released notices citing cyber vulnerabilities with four devices made by Baxter (NYSE:BAX).

Included among the devices listed by DHS were Baxter’s PrismaFlex/PrisMax devices, its ExactaMix, its Phoenix hemodialysis delivery system and its Sigma Spectrum infusion pumps.

All four notices included warnings regarding the devices’ Cleartext transmission of sensitive information. According to the notices, the affected devices do not implement data-in-transit encryption when configured to send treatment data to a patient data management system (PDMS), which could make the devices vulnerable to an attacker seeking to observe sensitive data.

The PrismaFlex system for acute kidney injury and the PrisMax system for delivering continuous renal replacement therapy and therapeutic plasma exchange both had vulnerabilities with improper authentication, meaning the devices could be susceptible to an attacker modifying treatment status information.

Additionally, according to the notice, the PrismaFlex includes a hard-coded service password with access to biomedical information, device settings, calibration settings and network configuration, which could allow an attacker to modify settings and calibration.

Baxter’s ExactaMix automated pumping system also had vulnerabilities with hard-coded service passwords, along with missing encryption of sensitive data, improper access control with its USB interface from an unauthorized user, exposure to non-administrative users seeking to access the operating system and edit the application startup script and improper input validation that can affect the control flow or data flow of a system.

The Phoenix hemodialysis delivery system’s only listed vulnerability in the notice was the Cleartext transmission issue, as an attacker could observe sensitive information sent between the Phoenix system and the Exalis tool.

Finally, the Sigma Spectrum infusion pumps also had vulnerabilities with the hard-coded passwords, as well as incorrect permission assignments for data stored on its wireless battery module (WBM) that permits temporary configuration changes and, when configured for wireless networking, the pumps had a vulnerability with operation on a resource after expiration or release, operating until the WBM is rebooted.

“We recently completed an extensive product security assessment of Baxter medical devices in use, including older versions of our products,” a Baxter spokesperson told MassDevice in a statement. “Our review identified a small number of vulnerabilities which are considered controlled risks that do not directly pose a risk to patient safety.

“Consistent with industry best practices, Baxter is voluntarily disclosing vulnerabilities in Sigma Spectrum, ExactaMix, Phoenix, Prismaflex and PrisMax devices. Baxter has worked with the Department of Homeland Security to release ICS-CERT security advisories and publish security bulletins on Baxter’s product security website to make customers and stakeholders aware of potential security issues and to share recommended mitigation actions.”

Filed Under: Dialysis, Electronic Medical Records (EMR), Featured, Health Technology, Regulatory/Compliance, Software / IT Tagged With: Baxter, U.S. Department of Homeland Security

More recent news

  • Former Shockwave Medical CEO joins Solenic Medical’s board
  • Anaconda Biomed brings in $56 million
  • Precision Neuroscience raises $250M in Series D for its BCI
  • Fresenius discontinuing Chinese sales of 4008A hemodialysis system
  • Perfuze’s super-bore stroke catheter tops conventional, cyclic aspiration in bench study

About Sean Whooley

Sean Whooley is a senior editor who mainly produces work for MassDevice, Medical Design & Outsourcing and Drug Delivery Business News. He received a bachelor's degree in multiplatform journalism from the University of Maryland, College Park. You can connect with him on LinkedIn or email him at [email protected].

Primary Sidebar

Cart

“md
EXPAND YOUR KNOWLEDGE AND STAY CONNECTED
Get the latest med device regulatory, business and technology news.

DeviceTalks Weekly

See More >
MDO ad
MDO ad

Footer

MASSDEVICE MEDICAL NETWORK

DeviceTalks
Drug Delivery Business News
Medical Design & Outsourcing
Medical Tubing + Extrusion
Drug Discovery & Development
Pharmaceutical Processing World
MedTech 100 Index
R&D World
Medical Design Sourcing

DeviceTalks Webinars, Podcasts, & Discussions

Attend our Monthly Webinars
Listen to our Weekly Podcasts
Join our DeviceTalks Tuesdays Discussion

MASSDEVICE

Subscribe to MassDevice E-Newsletter
Advertise with us
About
Contact us

Copyright © 2026 · Arrowfly LLC and its licensors. All rights reserved.
The material on this site may not be reproduced, distributed, transmitted, cached or otherwise used, except with the prior written permission of Arrowfly.

Privacy Policy