← Back

CVE-2022-26390

nvd nist
Published: Sep 9, 2022Modified: Nov 21, 2024

JSON object

Loading...
4.2
Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 0.5 / Impact: 3.6
Source: NVD

Description

The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.

Affected (9)

4 products
Configuration A
6 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Baxter
From 20d29 to 20d32
From 22d19 to 22d28
Version 16
Version 16d38
Version 17
Version 17d19
Running on/withPlatform Versions
Baxter
Spectrum Wireless Battery Module
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Baxter
Sigma Spectrum 35700bax
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Baxter
Sigma Spectrum 35700bax2
All versions
Configuration D
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Baxter
Baxter Spectrum Iq 35700bax3
All versions

References (3)

Source: productsecurity@baxter.com
Third Party AdvisoryUS Government Resource
Source: nvd@nist.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.