Lucene search

K
nvd[email protected]NVD:CVE-2022-26393
HistorySep 09, 2022 - 3:15 p.m.

CVE-2022-26393

2022-09-0915:15:09
CWE-134
web.nvd.nist.gov
1
baxter
spectrum wbm
format string attack
vulnerability
application messaging
memory read
sensitive information
denial of service

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.001 Low

EPSS

Percentile

42.8%

The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.

Affected configurations

NVD
Node
baxterspectrum_wireless_battery_module_firmwareMatch20d29
AND
baxterspectrum_wireless_battery_moduleMatch-
Node
baxtersigma_spectrum_35700bax_firmwareMatch-
AND
baxtersigma_spectrum_35700baxMatch-
Node
baxtersigma_spectrum_35700bax2Match-
AND
baxtersigma_spectrum_35700bax2_firmwareMatch-
Node
baxterbaxter_spectrum_iq_35700bax3Match-
AND
baxterbaxter_spectrum_iq_35700bax3_firmwareMatch-

8.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

0.001 Low

EPSS

Percentile

42.8%

Related for NVD:CVE-2022-26393