HIGH · 7.0

CVE-2022-22766

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for i...

Vulnerability Description

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.

CVSS Score

7.0

HIGH

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
BdPyxis Anesthesia Station Es FirmwareAll versions
BdPyxis Anesthesia Station Es-
BdPyxis Anesthesia Station 4000 FirmwareAll versions
BdPyxis Anesthesia Station 4000-
BdPyxis Cato FirmwareAll versions
BdPyxis Cato-
BdPyxis Ciisafe FirmwareAll versions
BdPyxis Ciisafe-
BdPyxis Inventory Connect FirmwareAll versions
BdPyxis Inventory Connect-
BdPyxis Iv Prep FirmwareAll versions
BdPyxis Iv Prep-
BdPyxis Jitrbud FirmwareAll versions
BdPyxis Jitrbud-
BdPyxis Kanban Rf FirmwareAll versions
BdPyxis Kanban Rf-
BdPyxis Logistics FirmwareAll versions
BdPyxis Logistics-
BdPyxis Med Link Family FirmwareAll versions
BdPyxis Med Link Family-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-22766?

CVE-2022-22766 is a vulnerability with a CVSS score of 7.0 (HIGH). Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for i...

How severe is CVE-2022-22766?

CVE-2022-22766 has been rated HIGH with a CVSS base score of 7.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-22766?

Check the references section above for vendor advisories and patch information. Affected products include: Bd Pyxis Anesthesia Station Es Firmware, Bd Pyxis Anesthesia Station Es, Bd Pyxis Anesthesia Station 4000 Firmware, Bd Pyxis Anesthesia Station 4000, Bd Pyxis Cato Firmware.