CVE-2022-22767: BD Pyxis™ Products – Default Credentials

Published Jun 1, 2022
·
Updated

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

Affected Software

32 affected components
BD Pyxis Anesthesia Station Es Firmware
BD Pyxis Anesthesia Station Es
BD Pyxis Ciisafe Firmware
BD Pyxis Ciisafe
BD Pyxis Logistics Firmware
BD Pyxis Logistics
BD Pyxis Medbank Firmware
BD Pyxis Medbank
BD Pyxis Medstation 4000 Firmware
BD Pyxis Medstation 4000
BD Pyxis Medstation Es Firmware
BD Pyxis MedStation ES
BD Pyxis Medstation Es Server Firmware
BD Pyxis Medstation Es Server
BD Pyxis Parassist Firmware
BD Pyxis Parassist
BD Pyxis Rapid Rx Firmware
BD Pyxis Rapid Rx
BD Pyxis Stockstation Firmware
BD Pyxis Stockstation
BD Pyxis Supplycenter Firmware
BD Pyxis Supplycenter
BD Pyxis Supplyroller Firmware
BD Pyxis Supplyroller
BD Pyxis Supplystation Firmware
BD Pyxis Supplystation
BD Pyxis Supplystation Ec Firmware
BD Pyxis Supplystation Ec
BD Pyxis Supplystation Rf Auxiliary Firmware
BD Pyxis Supplystation Rf Auxiliary
BD Rowa Pouch Packaging Systems Firmware
BD Rowa Pouch Packaging Systems

Remediation

Information

BD is currently strengthening our credential management capabilities in BD Pyxis™ products. Service personnel are proactively working with customers whose domain-joined server(s) credentials require updates. BD is currently piloting a credential management solution that is initially targeted for only specific BD Pyxis™ product versions and will allow for improved authentication management practices with specific local operating system credentials. Changes needed for installation, upgrade or to applications are being evaluated as part of the overall remediation.

Event History

Jun 1, 2022
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
RemedyDescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2022-22767?

CVE-2022-22767 is a vulnerability in specific BD Pyxis™ products that were installed with default credentials.

2

Which BD Pyxis™ products are affected by CVE-2022-22767?

BD Pyxis Anesthesia Station ES Firmware, BD Pyxis Ciisafe Firmware, BD Pyxis Logistics Firmware, BD Pyxis Medbank Firmware, BD Pyxis Medstation 4000 Firmware, BD Pyxis Medstation ES Firmware, BD Pyxis Medstation ES Server Firmware, BD Pyxis Parassist Firmware, BD Pyxis Rapid Rx Firmware, BD Pyxis Stockstation Firmware, BD Pyxis Supplycenter Firmware, BD Pyxis Supplyroller Firmware, BD Pyxis Supplystation Firmware, BD Pyxis Supplystation EC Firmware, BD Pyxis Supplystation RF Auxiliary Firmware, and BD Rowa Pouch Packaging Systems Firmware.

3

What is the severity of CVE-2022-22767?

The severity of CVE-2022-22767 is high, with a severity value of 8.8.

4

How do I fix the CVE-2022-22767 vulnerability?

To fix the CVE-2022-22767 vulnerability, you should update the affected BD Pyxis™ products to the latest firmware version and change the default credentials.

5

Where can I find more information about CVE-2022-22767?

You can find more information about CVE-2022-22767 at [this link](https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-credentials).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203