Risk | Low |
Patch available | NO |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2022-26390 CVE-2022-26392 CVE-2022-26394 |
CWE-ID | CWE-311 CWE-134 CWE-306 |
Exploitation vector | Network |
Public exploit | N/A |
Vulnerable software |
Sigma Spectrum model 35700BAX Hardware solutions / Medical equipment Sigma Spectrum model 35700BAX2 Hardware solutions / Medical equipment Baxter Spectrum IQ model 35700BAX3 Hardware solutions / Medical equipment Sigma Spectrum LVP Wireless Battery Modules Hardware solutions / Medical equipment Baxter Spectrum IQ LVP with Wireless Battery Modules Hardware solutions / Medical equipment |
Vendor | Baxter |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU67147
Risk: Low
CVSSv4.0: 0.6 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-26390
CWE-ID:
CWE-311 - Missing Encryption of Sensitive Data
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected application stores network credentials and patient health information (PHI) in unencrypted form. An attacker with physical access can gain unauthorized access to sensitive information on the system.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsSigma Spectrum model 35700BAX: 6.0
Sigma Spectrum model 35700BAX2: 8.0
Baxter Spectrum IQ model 35700BAX3: 9.0
Sigma Spectrum LVP Wireless Battery Modules: 16D38 - 22D28
Baxter Spectrum IQ LVP with Wireless Battery Modules: 22D19 - 22D28
CPE2.3https://ics-cert.us-cert.gov/advisories/icsma-22-251-01
https://www.baxter.com/sites/g/files/ebysai3896/files/2022-09/ICSMA-22-251-01.pdf
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67148
Risk: Low
CVSSv4.0: 0.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-26392
CWE-ID:
CWE-134 - Use of Externally-Controlled Format String
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to a format string error within the application messaging when in superuser mode. A remote user can read memory in the WBM and access sensitive information.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsSigma Spectrum model 35700BAX: 6.0
Sigma Spectrum model 35700BAX2: 8.0
Baxter Spectrum IQ model 35700BAX3: 9.0
Baxter Spectrum IQ LVP with Wireless Battery Modules: 22D19 - 22D28
Sigma Spectrum LVP Wireless Battery Modules: 16D38 - 20D32
CPE2.3https://ics-cert.us-cert.gov/advisories/icsma-22-251-01
https://www.baxter.com/sites/g/files/ebysai3896/files/2022-09/ICSMA-22-251-01.pdf
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU67150
Risk: Low
CVSSv4.0: 1.2 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-26394
CWE-ID:
CWE-306 - Missing Authentication for Critical Function
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not perform mutual authentication with the gateway server host. A remote user on the local network can perform a machine-in-the-middle attack that modifies parameters and make the network connection fail.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsSigma Spectrum model 35700BAX: 6.0
Sigma Spectrum model 35700BAX2: 8.0
Baxter Spectrum IQ model 35700BAX3: 9.0
Baxter Spectrum IQ LVP with Wireless Battery Modules: 22D19 - 22D28
Sigma Spectrum LVP Wireless Battery Modules: 16D38 - 20D32
CPE2.3https://ics-cert.us-cert.gov/advisories/icsma-22-251-01
https://www.baxter.com/sites/g/files/ebysai3896/files/2022-09/ICSMA-22-251-01.pdf
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.