CVE-2022-22767

Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:bd:pyxis_anesthesia_station_es_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_anesthesia_station_es:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:bd:pyxis_ciisafe_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_ciisafe:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:bd:pyxis_logistics_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_logistics:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:bd:pyxis_medbank_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_medbank:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:bd:pyxis_medstation_4000_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_medstation_4000:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:bd:pyxis_medstation_es_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_medstation_es:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:bd:pyxis_medstation_es_server_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_medstation_es_server:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:bd:pyxis_parassist_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_parassist:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:bd:pyxis_rapid_rx_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_rapid_rx:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:bd:pyxis_stockstation_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_stockstation:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:bd:pyxis_supplycenter_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_supplycenter:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:bd:pyxis_supplyroller_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_supplyroller:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:bd:pyxis_supplystation_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_supplystation:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:bd:pyxis_supplystation_ec_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_supplystation_ec:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:bd:pyxis_supplystation_rf_auxiliary_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:pyxis_supplystation_rf_auxiliary:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:bd:rowa_pouch_packaging_systems_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:bd:rowa_pouch_packaging_systems:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:47

Type Values Removed Values Added
References () https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-credentials - Vendor Advisory () https://cybersecurity.bd.com/bulletins-and-patches/bd-pyxis-products-default-credentials - Vendor Advisory

Information

Published : 2022-06-02 14:15

Updated : 2024-11-21 06:47


NVD link : CVE-2022-22767

Mitre link : CVE-2022-22767

CVE.ORG link : CVE-2022-22767


JSON object : View

Products Affected

bd

  • pyxis_medstation_es_firmware
  • pyxis_medstation_es_server_firmware
  • pyxis_parassist_firmware
  • pyxis_supplyroller
  • pyxis_supplystation_ec_firmware
  • pyxis_logistics_firmware
  • pyxis_stockstation
  • pyxis_anesthesia_station_es_firmware
  • pyxis_medbank_firmware
  • rowa_pouch_packaging_systems_firmware
  • pyxis_ciisafe
  • pyxis_logistics
  • pyxis_medstation_4000_firmware
  • pyxis_medstation_es_server
  • pyxis_supplycenter
  • rowa_pouch_packaging_systems
  • pyxis_medstation_4000
  • pyxis_medstation_es
  • pyxis_anesthesia_station_es
  • pyxis_supplycenter_firmware
  • pyxis_supplystation_ec
  • pyxis_rapid_rx_firmware
  • pyxis_parassist
  • pyxis_supplystation_rf_auxiliary_firmware
  • pyxis_stockstation_firmware
  • pyxis_supplystation
  • pyxis_supplystation_firmware
  • pyxis_rapid_rx
  • pyxis_medbank
  • pyxis_supplystation_rf_auxiliary
  • pyxis_supplyroller_firmware
  • pyxis_ciisafe_firmware
CWE
CWE-262

Not Using Password Aging

CWE-522

Insufficiently Protected Credentials