CVE-2022-26392: Format String vulnerability
The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26392?
CVE-2022-26392 has been classified as a critical vulnerability due to its potential to expose sensitive information.
How do I fix CVE-2022-26392?
To mitigate CVE-2022-26392, users should update the Baxter Spectrum Wireless Battery Module firmware to the latest version available.
What types of attacks can CVE-2022-26392 enable?
CVE-2022-26392 can enable format string attacks via application messaging, allowing unauthorized memory access.
Which versions of Baxter Spectrum Wireless Battery Module are affected by CVE-2022-26392?
CVE-2022-26392 affects Baxter Spectrum Wireless Battery Module firmware versions 16, 16D38, 17, and from 20D29 to 20D32.
What information can be accessed through CVE-2022-26392?
CVE-2022-26392 allows an attacker to read memory of the Baxter Spectrum WBM, potentially accessing sensitive information.