Format String vulnerability
CVE-2022-26392

3.1LOW

Key Information:

Vendor

Baxter

Vendor
CVE Published:
9 September 2022

What is CVE-2022-26392?

The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.

Affected Version(s)

Baxter Spectrum Wireless Battery Module (WBM) 16

Baxter Spectrum Wireless Battery Module (WBM) 16D38

Baxter Spectrum Wireless Battery Module (WBM) 17

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.