Product Security
In support of our mission to save and sustain lives, Baxter takes product security seriously. We have a dedicated global team committed to ensuring that our products are safe and secure for their intended clinical use. Security is integrated into product design and lifecycle management through Baxter’s product security process, which is guided by leading industry standards, regulations, and best practices.
Product Security Bulletins
Apache Log4j Vulnerability
Axeda agent and Axeda Desktop Server for Windows
Baxter Connex Health Portal Vulnerabilities
Baxter (Welch Allyn) Product Configuration Tool Vulnerability
ConnectWise Vulnerabilities
Connex Spot Monitor - ICS Advisory (ICSMA-24-74-X)
Critical Vulnerabilities in Microsoft Windows Operating Systems (AA20-014A)
ExactaMix – CERT/CC Vulnerability Note (VU#383432) – PrintNIghtmare
ExactaMix – ICS Advisory (ICMSA-20-170-01)
ExactaMix – Multiple Windows SMB Remote Code Execution Vulnerabilities
ExactaMix – Microsoft Security Advisory for CVE-2019-0708 "Remote Desktop Services, Remote Code Execution Vulnerability.”
IPnet and VxWorks Urgent/11 Advisory – No Impact to Baxter Products
Life2000 Ventilation System – ICS Advisory (ICSMA-24-319-01)
Phoenix – ICS Advisory (ICSMA-20-170-03)
Sigma Spectrum Infusion System Vulnerabilities – ICS Advisory (ICSA-15-181-01)
Spectrum V6, V8, V9 – ICS Advisory (ICSMA-22-251-01)
Spectrum V6, V8, V9 – ICS Advisory (ICSMA-20-170-04)
SweynTooth Vulnerabilities – No Impact to Baxter Products
Treck TCP/IP Stack (Ripple 20) Vulnerabilities (ICSA-20-168-01) - PrisMax
Treck TCP/IP Stack (Ripple 20) Vulnerabilities (ICSA-20-168-01) - Spectrum
Vulnerability in Mirth Connect
Additional Resources
Request a Document
To request the Baxter document(s) listed below, submit your request along with your business contact information (i.e. Your Name, Role, Company, Address, Phone Number) at the link below, or contact your Baxter service representative.
Product Security Questions
Customers with a specific question about any Baxter product can reach out to [email protected] or contact their Baxter service representative.
Global Privacy Policy
Baxter has established a Global Privacy Policy to reflect the foregoing principles which are a key part of Baxter company culture and operations.
Coordinated Vulnerability Disclosure Process
Baxter’s mission is to save and sustain lives. Fundamental to our mission and strategy is the commitment to designing, manufacturing, and maintaining safe and secure medical devices. We also know that cybersecurity threats and vulnerabilities change rapidly. We are therefore committed to working with the security researcher community to verify and respond to legitimate vulnerabilities, and we invite researchers to participate in our responsible reporting process outlined below:
Scope
Baxter created this coordinated disclosure process for security researchers to report potential cyber vulnerabilities related to Baxter’s commercially available products. It is not meant for technical support information on Baxter products or for reporting Adverse Events or Product Quality Complaints. For all of these other matters please engage with us via the appropriate reporting channel on our Contact Us page.
How to Submit
If you have discovered a potential cyber vulnerability related to a Baxter product, we ask you to contact us in English using the form below. Please encrypt your email using our GPG public key
Please include the following information in your submission:
- Technical description of the potential vulnerability and environment in which it was discovered
- Whether you believe multiple vendors are affected
- When and where the vulnerability was discovered
- Name, version, and configuration details of the affected product
- Specific potential impact and how you envision this vulnerability could be used in an attack
- Information about the tools and techniques you used to discover this vulnerability
- Any proof of concept or exploit code
- Any indications of the vulnerability being exploited
- Prior or intended disclosure of vulnerability information to other parties (e.g. regulators, vulnerability coordinators, vendors)
Please do not include any personally identifying information or sensitive health information.
What Baxter Will Do
- We will acknowledge receipt of the report .
- We will escalate credible reports to the appropriate team to verify and reproduce the reported vulnerability. You may be contacted during this time to support our verification efforts.
- We will evaluate the reported vulnerability and conduct a risk analysis to determine potential actions to be take.
- If the issue requires disclosure, Baxter will publish notification on https://www.www.kazihealthcare.com/product-security and will report to appropriate external parties.
Additional information For Security Researchers
To protect patients and their healthcare providers, any testing must comply with the following:
- Adhere to all applicable laws and regulations;
- Do not conduct any testing that requires social engineering or phishing attacks;
- Do not interfere, disrupt or otherwise impair the ordinary operation of any device, service, or the environment in which it runs.
- Do not conduct any testing that could harm patients or interrupt care, or downgrade of in-use safety functions.
- Do not conduct any testing that could manipulate clinical performance and/or data
- Do not conduct any testing that accesses, modifies, or copies personal data
- Do not test devices in use or software that is in a production environment
- Do not take actions to exploit any vulnerability
- Do not take actions that could make changes to a product or system after the test is completed
Notice
By submitting information through this process, you agree that your submission is voluntary, that it will be considered non-proprietary and non-confidential, and that Baxter is allowed to use the information in any manner, in whole or in part, without any restriction. You further acknowledge that the submission of any information does not create a contractual, partnership, employment or other legal relationship with Baxter. You also agree that submitting such information does not create any rights for you or any obligations for Baxter, nor does it limit Baxter’s rights to pursue remedies for conduct that violates laws or causes harm.
Security Research Contributions
Baxter acknowledges and appreciates the efforts of independent security researchers who contribute to the security of our products. These researchers have shown ethical conduct by adhering to Baxter's coordinated disclosure procedures or making substantial contributions to product security. The following independent security researchers are recognized for their valuable contributions to the security of Baxter's products.
We encourage all independent security researchers to continue their important work in maintaining the security of products used in healthcare, and we remain committed to fostering a collaborative and transparent relationship with the security research community.
2025
- Josh Dillon
Product Security, from Design to Delivery
Baxter’s product security program is built on four pillars: dedicated teams, rigorous design, transparency, and collaboration. Each element works together to ensure our devices remain safe, secure, and trusted throughout their lifecycle.
Dedicated Product Security Team
We are proud to have a global team of cybersecurity professionals dedicated to product security. Our team members are passionate about security and care about the safety of our patients. Our cybersecurity experts support both the secure development of new products and the sustained maintenance of our fielded devices. We know cybersecurity is a dynamic field and we are committed to protecting our patients throughout the entire product lifecycle.
Secure by Design
Baxter has a robust product security program focused on securing our products throughout their lifecycle, from inception to end of support. We take a collaborative approach, involving teams across Quality, Regulatory, Research and Development (R&D), Privacy, and Product Security. The program is informed by leading organizations including the U.S. Food and Drug Administration (FDA), National Institute of Standards and Technology (NIST), and the International Organization for Standardization (ISO). It is guided by regulations and requirements in the countries where we operate, such as the Health Insurance Portability and Accountability Act (HIPAA) in the U.S., and the General Data Protection Regulation (GDPR) in Europe. These standards contribute to the delivery of safe, reliable product.
Transparent Product Security Communications
Baxter is committed to communicating transparently with our customers about product security. We provide a Manufacturer Disclosure Statement for Medical Device Security (MDS2) in the industry standard format established by the National Electrical Manufacturers Association and the Healthcare Information and Management System Society, which describes important cybersecurity design features such as Audit Controls, User Identification and Authorization, Data Backup and Disaster Recovery, Malware Detection/ Protection, System and Application Hardening and Transmission Confidentiality and Integrity.
Additional information is available in user manuals and customer communications, and customers are encouraged to contact their Baxter representatives for support.
Strong Industry Partnerships
Baxter collaborates across the healthcare ecosystem to advance medical device security. We are actively engaged with organizations including:
- National Health Information Sharing and Analysis Center (NH-ISAC)
- Industrial Control Systems Cyber Emergency Response Team (ICS-CERT)
- Advanced Medical Technology Association (AdvaMed)
- Association for the Advancement of Medical Instrumentation (AAMI)
- Homeland Security Information Network (HSIN)
- Medical Device Innovation, Safety, and Security Consortium (MDISS)
- Medical Device Security Information Sharing Council (MDSISC)
- Medical Device Innovation Consortium (MDIC)
These partnerships ensure we stay ahead of emerging threats and align with best practices for patient safety.
Product Security Questions
Customers with a specific question about any Baxter product can reach out to our product security team via [email protected] or contact their Baxter service representative.
Data Privacy
Baxter’s global privacy program supports its product security commitments by ensuring that patients’, healthcare providers’, and customers’ personal information is protected and handled responsibly. The program helps ensure that Baxter products comply with data privacy principles and legal requirements under applicable privacy laws across our operations worldwide.