PT-2022-15658 · Bd+1 · Bd Viper Lt+1
Published
2022-02-12
·
Updated
2022-05-11
·
CVE-2022-22765
CVSS v3.1
8.0
High
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
BD Viper LT system versions 2.0 through 3.x
BD Viper LT system versions 4.0 and later
Description
The BD Viper LT system contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). Versions 4.0 and later utilize Microsoft Windows 10 and have additional Operating System hardening configurations which increase the attack complexity required to exploit this issue.
Recommendations
For BD Viper LT system versions 2.0 through 3.x, consider disabling access to sensitive information until a patch is available.
For BD Viper LT system versions 4.0 and later, ensure the additional Operating System hardening configurations are properly implemented to increase the attack complexity required to exploit this issue.
At the moment, there is no information about a newer version that contains a fix for this issue.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bd Viper Lt
Windows 10