CVE-2022-26392
Summary
| CVE | CVE-2022-26392 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-09-09 15:15:00 UTC |
| Updated | 2022-09-15 16:45:00 UTC |
| Description | The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information. |
Risk And Classification
Problem Types: CWE-134
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Baxter | Baxter Spectrum Iq 35700bax3 | - | All | All | All |
| Operating System | Baxter | Baxter Spectrum Iq 35700bax3 Firmware | - | All | All | All |
| Hardware | Baxter | Sigma Spectrum 35700bax | - | All | All | All |
| Hardware | Baxter | Sigma Spectrum 35700bax2 | - | All | All | All |
| Operating System | Baxter | Sigma Spectrum 35700bax2 Firmware | - | All | All | All |
| Operating System | Baxter | Sigma Spectrum 35700bax Firmware | - | All | All | All |
| Hardware | Baxter | Spectrum Wireless Battery Module | - | All | All | All |
| Operating System | Baxter | Spectrum Wireless Battery Module Firmware | 16 | All | All | All |
| Operating System | Baxter | Spectrum Wireless Battery Module Firmware | 16d38 | All | All | All |
| Operating System | Baxter | Spectrum Wireless Battery Module Firmware | 17 | All | All | All |
| Operating System | Baxter | Spectrum Wireless Battery Module Firmware | 17d19 | All | All | All |
| Operating System | Baxter | Spectrum Wireless Battery Module Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 404 - File Not Found | CISA | MISC | www.us-cert.gov | |
| Baxter Sigma Spectrum Infusion Pump | CISA | MISC | www.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.