MEDIUM · 5.5

CVE-2022-26394

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the networ...

Vulnerability Description

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
BaxterSpectrum Wireless Battery Module Firmware>= 20d29, <= 20d32
BaxterSpectrum Wireless Battery Module-
BaxterSigma Spectrum 35700Bax Firmware-
BaxterSigma Spectrum 35700Bax-
BaxterSigma Spectrum 35700Bax2 Firmware-
BaxterSigma Spectrum 35700Bax2-
BaxterBaxter Spectrum Iq 35700Bax3 Firmware-
BaxterBaxter Spectrum Iq 35700Bax3-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-26394?

CVE-2022-26394 is a vulnerability with a CVSS score of 5.5 (MEDIUM). The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the networ...

How severe is CVE-2022-26394?

CVE-2022-26394 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-26394?

Check the references section above for vendor advisories and patch information. Affected products include: Baxter Spectrum Wireless Battery Module Firmware, Baxter Spectrum Wireless Battery Module, Baxter Sigma Spectrum 35700Bax Firmware, Baxter Sigma Spectrum 35700Bax, Baxter Sigma Spectrum 35700Bax2 Firmware.