CVE-2022-26390

Published Sep 9, 2022

Last updated 6 months ago

Overview

Description
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Source
productsecurity@baxter.com
NVD status
Modified

Risk scores

CVSS 3.1

Type
Primary
Base score
4.2
Impact score
3.6
Exploitability score
0.5
Vector string
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
MEDIUM

Weaknesses

productsecurity@baxter.com
CWE-311
nvd@nist.gov
CWE-312

Social media

Hype score
Not currently trending

Configurations