8.8

CVE-2022-22767

BD Pyxis™ Products – Default Credentials

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bd ≫ Pyxis Ciisafe Firmware Version -
   Bd ≫ Pyxis Ciisafe Version -
Bd ≫ Pyxis Logistics Firmware Version -
   Bd ≫ Pyxis Logistics Version -
Bd ≫ Pyxis Medbank Firmware Version -
   Bd ≫ Pyxis Medbank Version -
Bd ≫ Pyxis Medstation 4000 Firmware Version -
   Bd ≫ Pyxis Medstation 4000 Version -
Bd ≫ Pyxis Medstation Es Firmware Version -
   Bd ≫ Pyxis Medstation Es Version -
Bd ≫ Pyxis Parassist Firmware Version -
   Bd ≫ Pyxis Parassist Version -
Bd ≫ Pyxis Rapid Rx Firmware Version -
   Bd ≫ Pyxis Rapid Rx Version -
Bd ≫ Pyxis Stockstation Firmware Version -
   Bd ≫ Pyxis Stockstation Version -
Bd ≫ Pyxis Supplycenter Firmware Version -
   Bd ≫ Pyxis Supplycenter Version -
Bd ≫ Pyxis Supplyroller Firmware Version -
   Bd ≫ Pyxis Supplyroller Version -
Bd ≫ Pyxis Supplystation Firmware Version -
   Bd ≫ Pyxis Supplystation Version -
Bd ≫ Pyxis Supplystation Ec Firmware Version -
   Bd ≫ Pyxis Supplystation Ec Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.41% 0.324
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 8.3 6.5 10
AV:A/AC:L/Au:N/C:C/I:C/A:C
cybersecurity@bd.com 8.8 2.8 5.9
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-262 Not Using Password Aging

The product does not have a mechanism in place for managing password aging.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-credentials
Vendor Advisory