CVE-2022-26390: Unencrypted internal storage of security credentials
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26390?
CVE-2022-26390 is considered a high severity vulnerability due to the risk of exposing sensitive patient data.
How do I fix CVE-2022-26390?
To fix CVE-2022-26390, ensure all data and settings on the Baxter Spectrum Wireless Battery Module are securely erased before disposal or servicing.
What are the risks associated with CVE-2022-26390?
The risks of CVE-2022-26390 include unauthorized access to sensitive network credentials and protected health information (PHI) by an attacker with physical access.
Which devices are affected by CVE-2022-26390?
CVE-2022-26390 affects various versions of the Baxter Spectrum Wireless Battery Module Firmware, specifically certain firmware versions ranging from 16 to 22.
Is there a patch available for CVE-2022-26390?
There is currently no specific patch mentioned for CVE-2022-26390; users should follow mitigation steps to prevent potential exploitation.