Format string error in Baxter products - CVE-2022-26392

 

Format string error in Baxter products - CVE-2022-26392

Published: September 9, 2022


Vulnerability identifier: #VU67148
CSH Severity: Low
CVSS v4: 2.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26392
CWE-ID: CWE-134
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to a format string error within the application messaging when in superuser mode. A remote user can read memory in the WBM and access sensitive information.


Affected software

Sigma Spectrum model 35700BAX2
Baxter Spectrum IQ model 35700BAX3
Sigma Spectrum model 35700BAX
Sigma Spectrum LVP Wireless Battery Modules
Baxter Spectrum IQ LVP with Wireless Battery Modules

How to mitigate CVE-2022-26392

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins