Unencrypted internal storage of security credentials
CVE-2022-26390
4.2MEDIUM
What is CVE-2022-26390?
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Affected Version(s)
Baxter Spectrum Wireless Battery Module (WBM) 16
Baxter Spectrum Wireless Battery Module (WBM) 16D38
Baxter Spectrum Wireless Battery Module (WBM) 17
References
CVSS V3.1
Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved