Vulnerability Description
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). BD Viper LT system versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this vulnerability.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bd | Viper Lt System Firmware | >= 2.0, < 4.80 |
| Bd | Viper Lt System | - |
Related Weaknesses (CWE)
References
- https://cybersecurity.bd.com/bulletins-and-patches/bd-viper-lt-system-%E2%80%93-Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-062-02Third Party AdvisoryUS Government Resource
- https://cybersecurity.bd.com/bulletins-and-patches/bd-viper-lt-system-%E2%80%93-Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsma-22-062-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2022-22765?
CVE-2022-22765 is a vulnerability with a CVSS score of 8.0 (HIGH). BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected he...
How severe is CVE-2022-22765?
CVE-2022-22765 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22765?
Check the references section above for vendor advisories and patch information. Affected products include: Bd Viper Lt System Firmware, Bd Viper Lt System.