Description
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.
Published: 2022-02-11
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Workaround

Limit physical access to the device to only authorized personnel. Tightly control management of BD Pyxis system credentials provided to authorized users. Isolate affected products in a secure VLAN or behind firewalls with restricted access that only permits communication with trusted hosts in other networks when needed. Monitor and log all network traffic attempting to reach the affected products for suspicious activity. Work with your local BD support team ensure all patching and virus definitions are up to date. The Pyxis Security Module for automated patching and virus definition management is provided to all accounts.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-27909 Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.
History

No history.

Subscriptions

Bd Pyxis Anesthesia Station 4000 Pyxis Anesthesia Station 4000 Firmware Pyxis Anesthesia Station Es Pyxis Anesthesia Station Es Firmware Pyxis Cato Pyxis Cato Firmware Pyxis Ciisafe Pyxis Ciisafe Firmware Pyxis Inventory Connect Pyxis Inventory Connect Firmware Pyxis Iv Prep Pyxis Iv Prep Firmware Pyxis Jitrbud Pyxis Jitrbud Firmware Pyxis Kanban Rf Pyxis Kanban Rf Firmware Pyxis Logistics Pyxis Logistics Firmware Pyxis Med Link Family Pyxis Med Link Family Firmware Pyxis Medbank Pyxis Medbank Firmware Pyxis Medstation 4000 Pyxis Medstation 4000 Firmware Pyxis Medstation Es Pyxis Medstation Es Firmware Pyxis Medstation Es Server Pyxis Medstation Es Server Firmware Pyxis Parassist Pyxis Parassist Firmware Pyxis Pharmopack Pyxis Pharmopack Firmware Pyxis Procedurestation Pyxis Procedurestation Firmware Pyxis Rapid Rx Pyxis Rapid Rx Firmware Pyxis Stockstation Pyxis Stockstation Firmware Pyxis Supplycenter Pyxis Supplycenter Firmware Pyxis Supplyroller Pyxis Supplyroller Firmware Pyxis Supplystation Pyxis Supplystation Firmware Pyxis Track And Deliver Pyxis Track And Deliver Firmware Rowa Pouch Packaging Systems Rowa Pouch Packaging Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: BD

Published:

Updated: 2024-09-16T19:15:26.998Z

Reserved: 2022-01-07T00:00:00.000Z

Link: CVE-2022-22766

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-02-11T19:15:08.850

Modified: 2024-11-21T06:47:24.280

Link: CVE-2022-22766

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses