Lucene search

K
nvd[email protected]NVD:CVE-2022-26394
HistorySep 09, 2022 - 3:15 p.m.

CVE-2022-26394

2022-09-0915:15:09
CWE-306
web.nvd.nist.gov
baxter spectrum wbm
mutual authentication
man-in-the-middle
network connections

5.4 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

0.0005 Low

EPSS

Percentile

16.2%

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

Affected configurations

NVD
Node
baxterspectrum_wireless_battery_module_firmwareRange20d2920d32
OR
baxterspectrum_wireless_battery_module_firmwareMatch16
OR
baxterspectrum_wireless_battery_module_firmwareMatch16d38
OR
baxterspectrum_wireless_battery_module_firmwareMatch17
OR
baxterspectrum_wireless_battery_module_firmwareMatch17d19
AND
baxterspectrum_wireless_battery_moduleMatch-
Node
baxtersigma_spectrum_35700bax_firmwareMatch-
AND
baxtersigma_spectrum_35700baxMatch-
Node
baxtersigma_spectrum_35700bax2_firmwareMatch-
AND
baxtersigma_spectrum_35700bax2Match-
Node
baxterbaxter_spectrum_iq_35700bax3_firmwareMatch-
AND
baxterbaxter_spectrum_iq_35700bax3Match-

5.4 Medium

CVSS3

Attack Vector

ADJACENT

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

0.0005 Low

EPSS

Percentile

16.2%

Related for NVD:CVE-2022-26394