« Volver al listado

CVE-2022-26394

Estado: ModificadaMedia (5.4)—

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (4)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2022-26394",
  "cveTags": [],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "productsecurity@baxter.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "productsecurity@baxter.com",
      "affectedData": [
        {
          "vendor": "Baxter",
          "product": "Baxter Spectrum Wireless Battery Module (WBM)",
          "versions": [
            {
              "status": "affected",
              "version": "16"
            },
            {
              "status": "affected",
              "version": "16D38"
            },
            {
              "status": "affected",
              "version": "17"
            },
            {
              "status": "affected",
              "version": "17D19"
            },
            {
              "status": "affected",
              "version": "20D29"
            },
            {
              "status": "affected",
              "version": "20D30"
            },
            {
              "status": "affected",
              "version": "20D31"
            },
            {
              "status": "affected",
              "version": "20D32"
            }
          ]
        }
      ]
    }
  ],
  "published": "2022-09-09T15:15:09.697",
  "references": [
    {
      "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx",
      "tags": [
        "Broken Link"
      ],
      "source": "productsecurity@baxter.com"
    },
    {
      "url": "https://www.cisa.gov/uscert/ics/advisories/icsma-22-251-01",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "nvd@nist.gov"
    },
    {
      "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx",
      "tags": [
        "Broken Link"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "productsecurity@baxter.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail."
    },
    {
      "lang": "es",
      "value": "Baxter Spectrum WBM no lleva a cabo una autenticación mutua con el host del servidor de la pasarela. Esto puede permitir a un atacante llevar a cabo un ataque de hombre en el medio que modifique los parámetros haciendo que la conexión de red falle"
    }
  ],
  "lastModified": "2026-06-17T04:35:09.283",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "34DB00B2-DE3D-4D7B-9F03-35060096C37C",
              "versionEndIncluding": "20d32",
              "versionStartIncluding": "20d29"
            },
            {
              "criteria": "cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "719496E8-9020-456F-8CCC-FDFE10CF2820"
            },
            {
              "criteria": "cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16d38:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "03DA9071-305A-4319-9807-1BD6F9EB8FDB"
            },
            {
              "criteria": "cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C68B374-58AD-4E71-9B83-3CA0241B8A4A"
            },
            {
              "criteria": "cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17d19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "85202DB1-56E1-43C6-81BC-C141862D72C0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:baxter:spectrum_wireless_battery_module:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "15E8AA9C-1024-482D-8636-551486698A8C"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:baxter:sigma_spectrum_35700bax_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1354B2D0-A259-4832-BB3D-BD9C157FB5C0"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:baxter:sigma_spectrum_35700bax:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2EAFF022-6879-4734-9AEB-DE45E6E235DE"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:baxter:sigma_spectrum_35700bax2_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2715381-CA8F-416B-B9AD-9CDBDC181338"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:baxter:sigma_spectrum_35700bax2:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "576C9566-DA3F-43E8-B4E8-C5DEF3B06696"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:baxter:baxter_spectrum_iq_35700bax3_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89AFD13D-97D8-40A5-B36B-9B65229302B1"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:baxter:baxter_spectrum_iq_35700bax3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "71D6364A-9707-4BB0-8808-AF3314026A79"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "productsecurity@baxter.com"
}