8.8

CVE-2022-22767

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
BdPyxis Ciisafe Firmware Version-
   BdPyxis Ciisafe Version-
BdPyxis Logistics Firmware Version-
   BdPyxis Logistics Version-
BdPyxis Medbank Firmware Version-
   BdPyxis Medbank Version-
BdPyxis Medstation 4000 Firmware Version-
   BdPyxis Medstation 4000 Version-
BdPyxis Medstation Es Firmware Version-
   BdPyxis Medstation Es Version-
BdPyxis Parassist Firmware Version-
   BdPyxis Parassist Version-
BdPyxis Rapid Rx Firmware Version-
   BdPyxis Rapid Rx Version-
BdPyxis Stockstation Firmware Version-
   BdPyxis Stockstation Version-
BdPyxis Supplycenter Firmware Version-
   BdPyxis Supplycenter Version-
BdPyxis Supplyroller Firmware Version-
   BdPyxis Supplyroller Version-
BdPyxis Supplystation Firmware Version-
   BdPyxis Supplystation Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.23% 0.453
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
cybersecurity@bd.com 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-262 Not Using Password Aging

The product does not have a mechanism in place for managing password aging.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.