The Baxter Connex Health Portal, formerly Hillrom and Welch Allyn, drew ICSMA-24-249-01. CVE-2024-6795, unauthenticated SQL injection, base score 10.0, plus CVE-2024-6796, an access-control flaw at 8.2.

SQL injection persists for a structural reason. When an application builds a query by pasting user input into the command text, the database cannot separate the developer's intent from the attacker's addition, and a string typed into a form becomes an instruction the server carries out. The unauthenticated form is the worst shape of the flaw, because the entry point sits in front of the login rather than behind it.

A maximum-severity SQL injection means a remote attacker with no credentials runs arbitrary SQL: read, alter or delete data, and admin actions like shutting down the database. On a patient health portal that is every record it holds. Baxter deployed a server-side fix, the one advantage of a hosted portal over shipped software, since the maker patches it once for everyone.

A health portal is built to be reached. It faces the public network by design so patients and clinicians can sign in from outside the hospital, which is what makes an unauthenticated flaw so serious. The same door that serves legitimate users serves the attacker, and behind it sits a database holding identifiers, contact details and clinical information in a single queryable place.

This is the second near-maximum SQL injection in this archive, alongside the Siemens imaging platform. The oldest web vulnerability in the book still lands critical findings on medical software. Parameterize every query.

The hosted model shaped the response as much as the flaw shaped the risk. Because the portal runs on infrastructure the maker controls, a single fix reaches every user at once, without the long tail of updates that shipped software drags behind it. That advantage runs both ways, since centralized services close quickly when the maker is attentive and concentrate sensitive data behind whatever the weakest query happens to be.