CVE-2022-26390 (GCVE-0-2022-26390)
Vulnerability from cvelistv5
Published
2022-09-09 14:40
Modified
2024-09-17 04:09
CWE
  • CWE-311 - Missing Encryption of Sensitive Data
Summary
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
References
Impacted products
Vendor Product Version
Baxter Baxter Spectrum Wireless Battery Module (WBM) Version: 16
Version: 16D38
Version: 17
Version: 17D19
Version: 20D29
Version: 20D30
Version: 20D31
Version: 20D32
Version: 22D19
Version: 22D20
Version: 22D21
Version: 22D22
Version: 22D23
Version: 22D24
Version: 22D25
Version: 22D26
Version: 22D27
Version: 22D28
Create a notification for this product.
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-03T05:03:32.877Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "Baxter Spectrum Wireless Battery Module (WBM)",
          "vendor": "Baxter",
          "versions": [
            {
              "status": "affected",
              "version": "16"
            },
            {
              "status": "affected",
              "version": "16D38"
            },
            {
              "status": "affected",
              "version": "17"
            },
            {
              "status": "affected",
              "version": "17D19"
            },
            {
              "status": "affected",
              "version": "20D29"
            },
            {
              "status": "affected",
              "version": "20D30"
            },
            {
              "status": "affected",
              "version": "20D31"
            },
            {
              "status": "affected",
              "version": "20D32"
            },
            {
              "status": "affected",
              "version": "22D19"
            },
            {
              "status": "affected",
              "version": "22D20"
            },
            {
              "status": "affected",
              "version": "22D21"
            },
            {
              "status": "affected",
              "version": "22D22"
            },
            {
              "status": "affected",
              "version": "22D23"
            },
            {
              "status": "affected",
              "version": "22D24"
            },
            {
              "status": "affected",
              "version": "22D25"
            },
            {
              "status": "affected",
              "version": "22D26"
            },
            {
              "status": "affected",
              "version": "22D27"
            },
            {
              "status": "affected",
              "version": "22D28"
            }
          ]
        }
      ],
      "datePublic": "2022-09-08T00:00:00.000Z",
      "descriptions": [
        {
          "lang": "en",
          "value": "The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn\u0027t had all data and settings erased may be able to extract sensitive information."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "HIGH",
            "attackVector": "PHYSICAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          }
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-311",
              "description": "CWE-311 Missing Encryption of Sensitive Data",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2022-09-09T14:40:06.000Z",
        "orgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
        "shortName": "Baxter"
      },
      "references": [
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"
        }
      ],
      "source": {
        "discovery": "EXTERNAL"
      },
      "title": "Unencrypted internal storage of security credentials",
      "x_generator": {
        "engine": "Vulnogram 0.0.9"
      },
      "x_legacyV4Record": {
        "CVE_data_meta": {
          "ASSIGNER": "productsecurity@baxter.com",
          "DATE_PUBLIC": "2022-09-08T22:03:00.000Z",
          "ID": "CVE-2022-26390",
          "STATE": "PUBLIC",
          "TITLE": "Unencrypted internal storage of security credentials"
        },
        "affects": {
          "vendor": {
            "vendor_data": [
              {
                "product": {
                  "product_data": [
                    {
                      "product_name": "Baxter Spectrum Wireless Battery Module (WBM)",
                      "version": {
                        "version_data": [
                          {
                            "version_affected": "=",
                            "version_name": "16",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "16D38",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "17",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "17D19",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "20D29",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "20D30",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "20D31",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "20D32",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D19",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D20",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D21",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D22",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D23",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D24",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D25",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D26",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D27",
                            "version_value": ""
                          },
                          {
                            "version_affected": "=",
                            "version_name": "22D28",
                            "version_value": ""
                          }
                        ]
                      }
                    }
                  ]
                },
                "vendor_name": "Baxter"
              }
            ]
          }
        },
        "data_format": "MITRE",
        "data_type": "CVE",
        "data_version": "4.0",
        "description": {
          "description_data": [
            {
              "lang": "eng",
              "value": "The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn\u0027t had all data and settings erased may be able to extract sensitive information."
            }
          ]
        },
        "generator": {
          "engine": "Vulnogram 0.0.9"
        },
        "impact": {
          "cvss": {
            "attackComplexity": "HIGH",
            "attackVector": "PHYSICAL",
            "availabilityImpact": "NONE",
            "baseScore": 4.2,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          }
        },
        "problemtype": {
          "problemtype_data": [
            {
              "description": [
                {
                  "lang": "eng",
                  "value": "CWE-311 Missing Encryption of Sensitive Data"
                }
              ]
            }
          ]
        },
        "references": {
          "reference_data": [
            {
              "name": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx",
              "refsource": "MISC",
              "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"
            }
          ]
        },
        "source": {
          "discovery": "EXTERNAL"
        }
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
    "assignerShortName": "Baxter",
    "cveId": "CVE-2022-26390",
    "datePublished": "2022-09-09T14:40:06.351Z",
    "dateReserved": "2022-03-03T00:00:00.000Z",
    "dateUpdated": "2024-09-17T04:09:45.443Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…