CVE-2022-26394: Unauthenticated network reconfiguration via TCP/UDP
The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26394?
CVE-2022-26394 has been rated as a significant risk due to its potential for enabling man-in-the-middle attacks.
How do I fix CVE-2022-26394?
To remediate CVE-2022-26394, ensure mutual authentication is implemented between the Baxter Spectrum WBM and the gateway server.
What are the affected software versions for CVE-2022-26394?
CVE-2022-26394 affects Baxter Spectrum Wireless Battery Module firmware versions 20d29 through 20d32, and versions 16, 16d38, and 17, 17d19.
What types of attacks are possible due to CVE-2022-26394?
CVE-2022-26394 could allow attackers to conduct man-in-the-middle attacks, potentially compromising data integrity.
Is my device vulnerable if it uses Baxter Spectrum Wireless Battery Module?
Devices using the affected versions of Baxter Spectrum Wireless Battery Module firmware are vulnerable under CVE-2022-26394.