CVE-2022-26394

The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16:*:*:*:*:*:*:*
cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16d38:*:*:*:*:*:*:*
cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17:*:*:*:*:*:*:*
cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17d19:*:*:*:*:*:*:*
cpe:2.3:h:baxter:spectrum_wireless_battery_module:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:baxter:sigma_spectrum_35700bax_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:baxter:sigma_spectrum_35700bax:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:baxter:sigma_spectrum_35700bax2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:baxter:sigma_spectrum_35700bax2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:baxter:baxter_spectrum_iq_35700bax3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:baxter:baxter_spectrum_iq_35700bax3:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:53

Type Values Removed Values Added
References () https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx - Broken Link () https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx - Broken Link
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : 5.5

Information

Published : 2022-09-09 15:15

Updated : 2024-11-21 06:53


NVD link : CVE-2022-26394

Mitre link : CVE-2022-26394

CVE.ORG link : CVE-2022-26394


JSON object : View

Products Affected

baxter

  • sigma_spectrum_35700bax
  • spectrum_wireless_battery_module_firmware
  • sigma_spectrum_35700bax2
  • baxter_spectrum_iq_35700bax3_firmware
  • sigma_spectrum_35700bax2_firmware
  • sigma_spectrum_35700bax_firmware
  • spectrum_wireless_battery_module
  • baxter_spectrum_iq_35700bax3
CWE
CWE-306

Missing Authentication for Critical Function