Lucene search

K
cvelistBaxterCVELIST:CVE-2022-26392
HistorySep 08, 2022 - 12:00 a.m.

CVE-2022-26392 Format String vulnerability

2022-09-0800:00:00
CWE-134
Baxter
www.cve.org
1
cve-2022-26392
format string
baxter spectrum wbm
superuser mode
application messaging
memory read

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.

CNA Affected

[
  {
    "product": "Baxter Spectrum Wireless Battery Module (WBM)",
    "vendor": "Baxter",
    "versions": [
      {
        "status": "affected",
        "version": "16  "
      },
      {
        "status": "affected",
        "version": "16D38  "
      },
      {
        "status": "affected",
        "version": "17  "
      },
      {
        "status": "affected",
        "version": "17D19  "
      },
      {
        "status": "affected",
        "version": "20D29  "
      },
      {
        "status": "affected",
        "version": "20D30  "
      },
      {
        "status": "affected",
        "version": "20D31  "
      },
      {
        "status": "affected",
        "version": "20D32  "
      }
    ]
  }
]

3.1 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

6.5 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

28.6%

Related for CVELIST:CVE-2022-26392