Baxter International · Vulnerability Disclosure

Baxter International Vulnerability Disclosure

Vulnerability disclosure

Baxter runs a published coordinated vulnerability disclosure (CVD) process for its commercially available medical products, with an OpenPGP key for encrypted submissions, a stated handling workflow, explicit rules of engagement written for a clinical-safety context, a researcher acknowledgements list, and an archive of product security bulletins. PRIOR-RUN CORRECTION: the automated probe had recorded https://www.baxter.com/vulnerability-disclosure as this program's source. That URL is a SOFT-404 - it returns HTTP 200 with a 55,729-byte page titled "The requested page was not found on our website". It has been replaced with the page that actually serves the policy.

Baxter International runs a coordinated vulnerability disclosure program on Hackerone. A dedicated security contact is published.

HealthcareMedical DevicesInfusion PumpsPatient MonitoringConnected HealthFortune 500
Program: Hackerone

Disclosure Policy

Security Contact

Contact
product_security_questionsBaxter directs product security questions to a product security team mailbox published on the policy page (address obfuscated by the site's email protection) or to a Baxter service representative.

Source

Vulnerability Disclosure

baxter-international-vulnerability-disclosure.yml Raw ↑
generated: '2026-09-04'
method: searched
source: https://www.baxter.com/about-baxter/governance/product-security
provider: Baxter International
providerId: baxter-international
program: Baxter Coordinated Vulnerability Disclosure Process
published: true
description: >-
  Baxter runs a published coordinated vulnerability disclosure (CVD) process for its
  commercially available medical products, with an OpenPGP key for encrypted submissions, a
  stated handling workflow, explicit rules of engagement written for a clinical-safety context,
  a researcher acknowledgements list, and an archive of product security bulletins.
  PRIOR-RUN CORRECTION: the automated probe had recorded
  https://www.baxter.com/vulnerability-disclosure as this program's source. That URL is a
  SOFT-404 - it returns HTTP 200 with a 55,729-byte page titled "The requested page was not
  found on our website". It has been replaced with the page that actually serves the policy.
policy_url: https://www.baxter.com/about-baxter/governance/product-security
canonical_note: >-
  https://www.baxter.com/product-security is live and 301-redirects to the canonical
  /about-baxter/governance/product-security.
submission:
  method: web form on the policy page
  encryption:
    supported: true
    key_type: OpenPGP
    key_id: '0xF236F901'
    key_url: https://www.baxter.com/sites/baxtercorpna/files/2026-08/baxter-product-security-gpg-public-key_0xf236f901_public.txt
    key_verified:
      fetched: '2026-09-04'
      http_status: 200
      content_type: text/plain
      bytes: 3299
      body_starts_with: '-----BEGIN PGP PUBLIC KEY BLOCK-----'
  requested_fields:
    - technical description of the potential vulnerability and the environment it was found in
    - whether multiple vendors are believed affected
    - when and where the vulnerability was discovered
    - name, version and configuration of the affected product
    - specific potential impact and envisioned attack path
    - tools and techniques used
    - proof of concept or exploit code
    - any indications of exploitation in the wild
    - prior or intended disclosure to other parties (regulators, coordinators, vendors)
  prohibited_in_submission:
    - personally identifying information
    - sensitive health information
scope:
  in_scope: Potential cyber vulnerabilities in Baxter's commercially available products
  out_of_scope:
    - technical support questions about Baxter products
    - adverse events
    - product quality complaints
handling_process:
  - Baxter acknowledges receipt of the report
  - credible reports are escalated to the appropriate team to verify and reproduce
  - the researcher may be contacted to support verification
  - Baxter evaluates the report and conducts a risk analysis to determine action
  - if disclosure is warranted, Baxter publishes a bulletin on its product security page and
    reports to appropriate external parties such as CERTs and ISAOs
rules_of_engagement:
  - adhere to all applicable laws and regulations
  - no social engineering or phishing
  - do not interfere with, disrupt or impair the ordinary operation of any device or service
  - no testing that could harm patients, interrupt care, or downgrade in-use safety functions
  - no testing that could manipulate clinical performance or data
  - no testing that accesses, modifies or copies personal data
  - do not test devices in use or software in a production environment
  - do not exploit any vulnerability found
  - do not leave changes to a product or system after testing completes
submission_terms: >-
  Baxter states submissions are voluntary, treated as non-proprietary and non-confidential,
  usable by Baxter without restriction, and that submitting creates no contractual, partnership
  or employment relationship and no obligation on Baxter.
acknowledgements:
  published: true
  url: https://www.baxter.com/about-baxter/governance/product-security
  researchers:
    - name: Josh Dillon
      year: 2025
bug_bounty:
  platform: HackerOne
  handle: baxterintl
  url: https://hackerone.com/baxterintl
  type: vulnerability-disclosure-program
  paid: unknown
  verified:
    fetched: '2026-09-04'
    http_status: 200
    method: >-
      Differential probe - hackerone.com/baxterintl returns 200 while a control handle
      (hackerone.com/zzz-not-a-real-program-xyz9) returns 404, so the program handle exists.
      The page body is a JavaScript shell and hackerone.com/baxterintl.json returns 404
      unauthenticated, so the policy text, scope and any bounty amounts could not be read
      anonymously and are NOT asserted here.
    caveat: >-
      The program does not appear in HackerOne's unauthenticated public directory search
      (programs/search?query=handle:baxterintl returned zero results), which is consistent with
      an unlisted or VDP-only program. Baxter's own page does not link to HackerOne, so the
      relationship between the two intake routes is not stated by the provider.
advisories:
  published: true
  url: https://www.baxter.com/about-baxter/governance/product-security
  format: PDF bulletins linked from the product security page
  count_listed: 25
  examples:
    - Spectrum V6, V8, V9 - ICS Advisory (ICSMA-22-251-01)
    - Connex Spot Monitor - ICS Advisory (ICSMA-24-74-X)
    - Life2000 Ventilation System - ICS Advisory (ICSMA-24-319-01)
    - Baxter Connex Health Portal Vulnerabilities
    - Baxter (Welch Allyn) Product Configuration Tool Vulnerability
    - Starling Historical Vulnerabilities
    - Vulnerability in Mirth Connect
    - Treck TCP/IP Stack (Ripple 20) Vulnerabilities (ICSA-20-168-01) - PrisMax and Spectrum
  note: >-
    Bulletins are served from a Baxter-controlled CDN (p1.aprimocdn.net/hillrom/...), a hosting
    path inherited from the Hillrom acquisition. Several bulletins state "no impact to Baxter
    products", so the list is a disclosure record rather than a defect list.
contact:
  product_security_questions: >-
    Baxter directs product security questions to a product security team mailbox published on
    the policy page (address obfuscated by the site's email protection) or to a Baxter service
    representative.
gaps:
  - No /.well-known/security.txt on any Baxter, Hillrom or Welch Allyn host (RFC 9116 absent).
  - No stated acknowledgement SLA in days on the current page; an earlier version of the policy
    stated 7 days, which the current text does not repeat, so no SLA is asserted here.
  - No CSAF/VEX machine-readable advisory feed; bulletins are PDF only.
  - No SBOM publication statement.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/baxter-international-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.