generated: '2026-09-04' method: searched source: https://www.baxter.com/about-baxter/governance/product-security provider: Baxter International providerId: baxter-international program: Baxter Coordinated Vulnerability Disclosure Process published: true description: >- Baxter runs a published coordinated vulnerability disclosure (CVD) process for its commercially available medical products, with an OpenPGP key for encrypted submissions, a stated handling workflow, explicit rules of engagement written for a clinical-safety context, a researcher acknowledgements list, and an archive of product security bulletins. PRIOR-RUN CORRECTION: the automated probe had recorded https://www.baxter.com/vulnerability-disclosure as this program's source. That URL is a SOFT-404 - it returns HTTP 200 with a 55,729-byte page titled "The requested page was not found on our website". It has been replaced with the page that actually serves the policy. policy_url: https://www.baxter.com/about-baxter/governance/product-security canonical_note: >- https://www.baxter.com/product-security is live and 301-redirects to the canonical /about-baxter/governance/product-security. submission: method: web form on the policy page encryption: supported: true key_type: OpenPGP key_id: '0xF236F901' key_url: https://www.baxter.com/sites/baxtercorpna/files/2026-08/baxter-product-security-gpg-public-key_0xf236f901_public.txt key_verified: fetched: '2026-09-04' http_status: 200 content_type: text/plain bytes: 3299 body_starts_with: '-----BEGIN PGP PUBLIC KEY BLOCK-----' requested_fields: - technical description of the potential vulnerability and the environment it was found in - whether multiple vendors are believed affected - when and where the vulnerability was discovered - name, version and configuration of the affected product - specific potential impact and envisioned attack path - tools and techniques used - proof of concept or exploit code - any indications of exploitation in the wild - prior or intended disclosure to other parties (regulators, coordinators, vendors) prohibited_in_submission: - personally identifying information - sensitive health information scope: in_scope: Potential cyber vulnerabilities in Baxter's commercially available products out_of_scope: - technical support questions about Baxter products - adverse events - product quality complaints handling_process: - Baxter acknowledges receipt of the report - credible reports are escalated to the appropriate team to verify and reproduce - the researcher may be contacted to support verification - Baxter evaluates the report and conducts a risk analysis to determine action - if disclosure is warranted, Baxter publishes a bulletin on its product security page and reports to appropriate external parties such as CERTs and ISAOs rules_of_engagement: - adhere to all applicable laws and regulations - no social engineering or phishing - do not interfere with, disrupt or impair the ordinary operation of any device or service - no testing that could harm patients, interrupt care, or downgrade in-use safety functions - no testing that could manipulate clinical performance or data - no testing that accesses, modifies or copies personal data - do not test devices in use or software in a production environment - do not exploit any vulnerability found - do not leave changes to a product or system after testing completes submission_terms: >- Baxter states submissions are voluntary, treated as non-proprietary and non-confidential, usable by Baxter without restriction, and that submitting creates no contractual, partnership or employment relationship and no obligation on Baxter. acknowledgements: published: true url: https://www.baxter.com/about-baxter/governance/product-security researchers: - name: Josh Dillon year: 2025 bug_bounty: platform: HackerOne handle: baxterintl url: https://hackerone.com/baxterintl type: vulnerability-disclosure-program paid: unknown verified: fetched: '2026-09-04' http_status: 200 method: >- Differential probe - hackerone.com/baxterintl returns 200 while a control handle (hackerone.com/zzz-not-a-real-program-xyz9) returns 404, so the program handle exists. The page body is a JavaScript shell and hackerone.com/baxterintl.json returns 404 unauthenticated, so the policy text, scope and any bounty amounts could not be read anonymously and are NOT asserted here. caveat: >- The program does not appear in HackerOne's unauthenticated public directory search (programs/search?query=handle:baxterintl returned zero results), which is consistent with an unlisted or VDP-only program. Baxter's own page does not link to HackerOne, so the relationship between the two intake routes is not stated by the provider. advisories: published: true url: https://www.baxter.com/about-baxter/governance/product-security format: PDF bulletins linked from the product security page count_listed: 25 examples: - Spectrum V6, V8, V9 - ICS Advisory (ICSMA-22-251-01) - Connex Spot Monitor - ICS Advisory (ICSMA-24-74-X) - Life2000 Ventilation System - ICS Advisory (ICSMA-24-319-01) - Baxter Connex Health Portal Vulnerabilities - Baxter (Welch Allyn) Product Configuration Tool Vulnerability - Starling Historical Vulnerabilities - Vulnerability in Mirth Connect - Treck TCP/IP Stack (Ripple 20) Vulnerabilities (ICSA-20-168-01) - PrisMax and Spectrum note: >- Bulletins are served from a Baxter-controlled CDN (p1.aprimocdn.net/hillrom/...), a hosting path inherited from the Hillrom acquisition. Several bulletins state "no impact to Baxter products", so the list is a disclosure record rather than a defect list. contact: product_security_questions: >- Baxter directs product security questions to a product security team mailbox published on the policy page (address obfuscated by the site's email protection) or to a Baxter service representative. gaps: - No /.well-known/security.txt on any Baxter, Hillrom or Welch Allyn host (RFC 9116 absent). - No stated acknowledgement SLA in days on the current page; an earlier version of the policy stated 7 days, which the current text does not repeat, so no SLA is asserted here. - No CSAF/VEX machine-readable advisory feed; bulletins are PDF only. - No SBOM publication statement. maintainers: - FN: Kin Lane email: kin@apievangelist.com