First published: Fri Sep 09 2022(Updated: )
The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information.
Credit: productsecurity@baxter.com
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Spectrum Wireless Battery Module | >=20d29<=20d32 | |
Baxter Spectrum Wireless Battery Module | >=22d19<=22d28 | |
Baxter Spectrum Wireless Battery Module | =16 | |
Baxter Spectrum Wireless Battery Module | =16d38 | |
Baxter Spectrum Wireless Battery Module | =17 | |
Baxter Spectrum Wireless Battery Module | =17d19 | |
Baxter Spectrum Wireless Battery Module Firmware | ||
Baxter Sigma Spectrum Infusion System Firmware | ||
Baxter Sigma Spectrum 35700bax Firmware | ||
Baxter Sigma Spectrum 35700bax2 | ||
Baxter Sigma Spectrum 35700bax2 Firmware | ||
Baxter Spectrum IQ 35700BAX3 Firmware | ||
Baxter Sigma Spectrum Infusion System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-26390 is considered a high severity vulnerability due to the risk of exposing sensitive patient data.
To fix CVE-2022-26390, ensure all data and settings on the Baxter Spectrum Wireless Battery Module are securely erased before disposal or servicing.
The risks of CVE-2022-26390 include unauthorized access to sensitive network credentials and protected health information (PHI) by an attacker with physical access.
CVE-2022-26390 affects various versions of the Baxter Spectrum Wireless Battery Module Firmware, specifically certain firmware versions ranging from 16 to 22.
There is currently no specific patch mentioned for CVE-2022-26390; users should follow mitigation steps to prevent potential exploitation.