Unencrypted internal storage of security credentials
CVE-2022-26390

4.2MEDIUM

Key Information:

Vendor

Baxter

Vendor
CVE Published:
8 September 2022

What is CVE-2022-26390?

The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.

Affected Version(s)

Baxter Spectrum Wireless Battery Module (WBM) 16

Baxter Spectrum Wireless Battery Module (WBM) 16D38

Baxter Spectrum Wireless Battery Module (WBM) 17

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.