PT-2022-17823 · Baxter · Baxter Spectrum Wireless Battery Module

Deral Heiland

·

Published

2022-09-09

·

Updated

2023-07-11

·

CVE-2022-26390

CVSS v3.1

4.2

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Baxter Spectrum Wireless Battery Module (WBM) (affected versions not specified)
Description The issue concerns the storage of network credentials and Protected Health Information (PHI) in unencrypted form, specifically applicable to Spectrum IQ pumps using auto programming. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Encryption of Sensitive Data

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

CVE-2022-26390

Affected Products

Baxter Spectrum Wireless Battery Module