8.8
CWE
522 262
Advisory Published
Updated

CVE-2022-22767: BD Pyxis™ Products – Default Credentials

First published: Wed Jun 01 2022(Updated: )

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

Credit: cybersecurity@bd.com

Affected SoftwareAffected VersionHow to fix
Bd Pyxis Anesthesia Station Es Firmware
Bd Pyxis Anesthesia Station Es
Bd Pyxis Ciisafe Firmware
Bd Pyxis Ciisafe
Bd Pyxis Logistics Firmware
Bd Pyxis Logistics
Bd Pyxis Medbank Firmware
Bd Pyxis Medbank
Bd Pyxis Medstation 4000 Firmware
Bd Pyxis Medstation 4000
Bd Pyxis Medstation Es Firmware
BD Pyxis MedStation ES
Bd Pyxis Medstation Es Server Firmware
Bd Pyxis Medstation Es Server
Bd Pyxis Parassist Firmware
Bd Pyxis Parassist
Bd Pyxis Rapid Rx Firmware
Bd Pyxis Rapid Rx
Bd Pyxis Stockstation Firmware
Bd Pyxis Stockstation
Bd Pyxis Supplycenter Firmware
Bd Pyxis Supplycenter
Bd Pyxis Supplyroller Firmware
Bd Pyxis Supplyroller
Bd Pyxis Supplystation Firmware
Bd Pyxis Supplystation
Bd Pyxis Supplystation Ec Firmware
Bd Pyxis Supplystation Ec
Bd Pyxis Supplystation Rf Auxiliary Firmware
Bd Pyxis Supplystation Rf Auxiliary
Bd Rowa Pouch Packaging Systems Firmware
Bd Rowa Pouch Packaging Systems

Remedy

BD is currently strengthening our credential management capabilities in BD Pyxis™ products. Service personnel are proactively working with customers whose domain-joined server(s) credentials require updates. BD is currently piloting a credential management solution that is initially targeted for only specific BD Pyxis™ product versions and will allow for improved authentication management practices with specific local operating system credentials. Changes needed for installation, upgrade or to applications are being evaluated as part of the overall remediation.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2022-22767?

    CVE-2022-22767 is a vulnerability in specific BD Pyxis™ products that were installed with default credentials.

  • Which BD Pyxis™ products are affected by CVE-2022-22767?

    BD Pyxis Anesthesia Station ES Firmware, BD Pyxis Ciisafe Firmware, BD Pyxis Logistics Firmware, BD Pyxis Medbank Firmware, BD Pyxis Medstation 4000 Firmware, BD Pyxis Medstation ES Firmware, BD Pyxis Medstation ES Server Firmware, BD Pyxis Parassist Firmware, BD Pyxis Rapid Rx Firmware, BD Pyxis Stockstation Firmware, BD Pyxis Supplycenter Firmware, BD Pyxis Supplyroller Firmware, BD Pyxis Supplystation Firmware, BD Pyxis Supplystation EC Firmware, BD Pyxis Supplystation RF Auxiliary Firmware, and BD Rowa Pouch Packaging Systems Firmware.

  • What is the severity of CVE-2022-22767?

    The severity of CVE-2022-22767 is high, with a severity value of 8.8.

  • How do I fix the CVE-2022-22767 vulnerability?

    To fix the CVE-2022-22767 vulnerability, you should update the affected BD Pyxis™ products to the latest firmware version and change the default credentials.

  • Where can I find more information about CVE-2022-22767?

    You can find more information about CVE-2022-22767 at [this link](https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-credentials).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203