CVE-2022-26390
09.09.2022, 15:15
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
baxter | spectrum_wireless_battery_module_firmware | 20d29 ≤ 𝑥 ≤ 20d32 |
baxter | spectrum_wireless_battery_module_firmware | 22d19 ≤ 𝑥 ≤ 22d28 |
baxter | sigma_spectrum_35700bax_firmware | - |
baxter | sigma_spectrum_35700bax2_firmware | - |
baxter | baxter_spectrum_iq_35700bax3_firmware | - |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-311 - Missing Encryption of Sensitive DataThe software does not encrypt sensitive or critical information before storage or transmission.
- CWE-312 - Cleartext Storage of Sensitive InformationThe product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.