Missing Authentication for Critical Function in Baxter products - CVE-2022-26394
Published: September 9, 2022
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected application does not perform mutual authentication with the gateway server host. A remote user on the local network can perform a machine-in-the-middle attack that modifies parameters and make the network connection fail.
Affected software
Baxter Spectrum IQ model 35700BAX3
Sigma Spectrum model 35700BAX
Sigma Spectrum LVP Wireless Battery Modules
Baxter Spectrum IQ LVP with Wireless Battery Modules