MEDIUM · 4.2

CVE-2022-26390

The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access...

Vulnerability Description

The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.

CVSS Score

4.2

MEDIUM

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
PHYSICAL
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
BaxterSpectrum Wireless Battery Module Firmware>= 20d29, <= 20d32
BaxterSpectrum Wireless Battery Module-
BaxterSigma Spectrum 35700Bax Firmware-
BaxterSigma Spectrum 35700Bax-
BaxterSigma Spectrum 35700Bax2 Firmware-
BaxterSigma Spectrum 35700Bax2-
BaxterBaxter Spectrum Iq 35700Bax3 Firmware-
BaxterBaxter Spectrum Iq 35700Bax3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-26390?

CVE-2022-26390 is a vulnerability with a CVSS score of 4.2 (MEDIUM). The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access...

How severe is CVE-2022-26390?

CVE-2022-26390 has been rated MEDIUM with a CVSS base score of 4.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-26390?

Check the references section above for vendor advisories and patch information. Affected products include: Baxter Spectrum Wireless Battery Module Firmware, Baxter Spectrum Wireless Battery Module, Baxter Sigma Spectrum 35700Bax Firmware, Baxter Sigma Spectrum 35700Bax, Baxter Sigma Spectrum 35700Bax2 Firmware.