PT-2022-3932 · Bd · Bd Pyxis

Published

2022-01-07

·

Updated

2022-06-11

·

CVE-2022-22767

CVSS v3.1

8.8

High

VectorAV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions BD Pyxis (affected versions not specified)
Description The issue is related to insufficient protection of registration data in BD Pyxis products, which may still operate with default credentials. This could allow threat actors to gain privileged access to the underlying file system and potentially exploit or gain access to electronic protected health information (ePHI) or other sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Insufficiently Protected Credentials

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04761
CVE-2022-22767

Affected Products

Bd Pyxis