Lucene search

K
cvelistBDCVELIST:CVE-2022-22767
HistoryJun 01, 2022 - 4:35 p.m.

CVE-2022-22767 BD Pyxis™ Products – Default Credentials

2022-06-0116:35:38
CWE-262
BD
www.cve.org
2
cve-2022-22767
default credentials
bd pyxis™ products
privileged access
ephi
sensitive information

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

26.4%

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

CNA Affected

[
  {
    "product": "BD Pyxis™ Anesthesia ES Station",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ CIISafe",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ Logistics",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ MedBank",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ MedStation™ 4000",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ MedStation™ ES",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ MedStation™ ES Server",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ ParAssist",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ Rapid Rx",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ StockStation",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ SupplyCenter",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ SupplyRoller",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ SupplyStation™",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ SupplyStation™ EC",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Pyxis™ SupplyStation™ RF auxiliary",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  },
  {
    "product": "BD Rowa™ Pouch Packaging Systems",
    "vendor": "Becton Dickinson (BD)",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

8.9

Confidence

High

EPSS

0.001

Percentile

26.4%

Related for CVELIST:CVE-2022-22767