SB2022060111 - Not Using Password Aging in BD Pyxis



SB2022060111 - Not Using Password Aging in BD Pyxis

Published: June 1, 2022

Security Bulletin ID SB2022060111
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Adjecent network
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Not Using Password Aging (CVE-ID: CVE-2022-22767)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to the affected products are installed with default credentials and may still operate with these credentials. A remote attacker on the local network can gain privileged access to the underlying file system and gain access to ePHI or other sensitive information. 


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.