logo

CISA Flags ICS Bugs in Baxter, Mitsubishi Products

ID: 26346903-8b09-562c-b504-6beeff0e30bf

STIX ID: report--26346903-8b09-562c-b504-6beeff0e30bf

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-09-06

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

CISA warned of multiple high-severity vulnerabilities impacting Baxter’s Connex Health Portal (notably a CVSS 10.0 SQL injection, CVE-2024-6795, and an 8.2 improper access control issue, CVE-2024-6796) and Mitsubishi MELSEC programmable controllers (ongoing DoS-related advisories for CVE-2020-5652 and CVE-2022-33324). Vendors have published fixes and mitigations; CISA recommends reducing network exposure, using firewalls and secure remote access, and applying vendor updates. While no exploit activity has been reported for the Baxter flaws, the advisory emphasizes elevated risk to healthcare and manufacturing given recent ransomware attacks and widespread unpatched vulnerabilities.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.