CVE-2022-22767

HIGHCVSS 8.8/10EPSS 0.41%

Last modified

CVE-2022-22767 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. EPSS estimates a 0.41% chance of exploitation in the next 30 days.

Description

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

Metrics

CVSS 3.1
8.8/10

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
0.41%

32.6th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BdPyxis Anesthesia Station Es FirmwareAll versions
BdPyxis Ciisafe FirmwareAll versions
BdPyxis Logistics FirmwareAll versions
BdPyxis Medbank FirmwareAll versions
BdPyxis Medstation 4000 FirmwareAll versions
BdPyxis Medstation Es FirmwareAll versions
BdPyxis Medstation Es Server FirmwareAll versions
BdPyxis Parassist FirmwareAll versions
BdPyxis Rapid Rx FirmwareAll versions
BdPyxis Stockstation FirmwareAll versions
BdPyxis Supplycenter FirmwareAll versions
BdPyxis Supplyroller FirmwareAll versions
BdPyxis Supplystation FirmwareAll versions
BdPyxis Supplystation Ec FirmwareAll versions
BdPyxis Supplystation Rf Auxiliary FirmwareAll versions
BdRowa Pouch Packaging Systems FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-22767?
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
How severe is CVE-2022-22767?
CVE-2022-22767 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.41% probability of exploitation in the next 30 days.
How do I fix CVE-2022-22767?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-22767?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST