Lucene search

K
cvelistBaxterCVELIST:CVE-2022-26394
HistorySep 08, 2022 - 12:00 a.m.

CVE-2022-26394 Unauthenticated network reconfiguration via TCP/UDP

2022-09-0800:00:00
CWE-306
Baxter
www.cve.org
1
cve-2022-26394
unauthenticated
network reconfiguration
tcp
udp
baxter spectrum wbm
mutual authentication
gateway server host
man in the middle
network connection failure.

5.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

5.8 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.2%

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

CNA Affected

[
  {
    "product": "Baxter Spectrum Wireless Battery Module (WBM)",
    "vendor": "Baxter",
    "versions": [
      {
        "status": "affected",
        "version": "16  "
      },
      {
        "status": "affected",
        "version": "16D38  "
      },
      {
        "status": "affected",
        "version": "17  "
      },
      {
        "status": "affected",
        "version": "17D19  "
      },
      {
        "status": "affected",
        "version": "20D29  "
      },
      {
        "status": "affected",
        "version": "20D30  "
      },
      {
        "status": "affected",
        "version": "20D31  "
      },
      {
        "status": "affected",
        "version": "20D32  "
      }
    ]
  }
]

5.5 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

5.8 Medium

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

16.2%

Related for CVELIST:CVE-2022-26394