PT-2022-15658 · Bd+1 · Bd Viper Lt+1

Published

2022-02-12

·

Updated

2022-05-11

·

CVE-2022-22765

CVSS v3.1

8.0

High

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions BD Viper LT system versions 2.0 through 3.x BD Viper LT system versions 4.0 and later
Description The BD Viper LT system contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). Versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this issue.
Recommendations For BD Viper LT system versions 2.0 through 3.x, consider disabling access to sensitive information until a patch is available. For BD Viper LT system versions 4.0 and later, ensure the additional Operating System hardening configurations are properly implemented to increase the attack complexity required to exploit this issue. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22765

Affected Products

Bd Viper Lt
Windows 10