Vulnerability Description
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bd | Pyxis Anesthesia Station Es Firmware | - |
| Bd | Pyxis Anesthesia Station Es | - |
| Bd | Pyxis Ciisafe Firmware | - |
| Bd | Pyxis Ciisafe | - |
| Bd | Pyxis Logistics Firmware | - |
| Bd | Pyxis Logistics | - |
| Bd | Pyxis Medbank Firmware | - |
| Bd | Pyxis Medbank | - |
| Bd | Pyxis Medstation 4000 Firmware | - |
| Bd | Pyxis Medstation 4000 | - |
| Bd | Pyxis Medstation Es Firmware | - |
| Bd | Pyxis Medstation Es | - |
| Bd | Pyxis Medstation Es Server Firmware | - |
| Bd | Pyxis Medstation Es Server | - |
| Bd | Pyxis Parassist Firmware | - |
| Bd | Pyxis Parassist | - |
| Bd | Pyxis Rapid Rx Firmware | - |
| Bd | Pyxis Rapid Rx | - |
| Bd | Pyxis Stockstation Firmware | - |
| Bd | Pyxis Stockstation | - |
Related Weaknesses (CWE)
References
- https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-creVendor Advisory
- https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-creVendor Advisory
FAQ
What is CVE-2022-22767?
CVE-2022-22767 is a vulnerability with a CVSS score of 8.8 (HIGH). Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same ...
How severe is CVE-2022-22767?
CVE-2022-22767 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-22767?
Check the references section above for vendor advisories and patch information. Affected products include: Bd Pyxis Anesthesia Station Es Firmware, Bd Pyxis Anesthesia Station Es, Bd Pyxis Ciisafe Firmware, Bd Pyxis Ciisafe, Bd Pyxis Logistics Firmware.