Description
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Published: 2022-06-01
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

BD is currently strengthening our credential management capabilities in BD Pyxis™ products. Service personnel are proactively working with customers whose domain-joined server(s) credentials require updates. BD is currently piloting a credential management solution that is initially targeted for only specific BD Pyxis™ product versions and will allow for improved authentication management practices with specific local operating system credentials. Changes needed for installation, upgrade or to applications are being evaluated as part of the overall remediation.


Vendor Workaround

Limit physical access to only authorized personnel.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2022-27910 Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
History

No history.

Subscriptions

Bd Pyxis Anesthesia Station Es Pyxis Anesthesia Station Es Firmware Pyxis Ciisafe Pyxis Ciisafe Firmware Pyxis Logistics Pyxis Logistics Firmware Pyxis Medbank Pyxis Medbank Firmware Pyxis Medstation 4000 Pyxis Medstation 4000 Firmware Pyxis Medstation Es Pyxis Medstation Es Firmware Pyxis Medstation Es Server Pyxis Medstation Es Server Firmware Pyxis Parassist Pyxis Parassist Firmware Pyxis Rapid Rx Pyxis Rapid Rx Firmware Pyxis Stockstation Pyxis Stockstation Firmware Pyxis Supplycenter Pyxis Supplycenter Firmware Pyxis Supplyroller Pyxis Supplyroller Firmware Pyxis Supplystation Pyxis Supplystation Ec Pyxis Supplystation Ec Firmware Pyxis Supplystation Firmware Pyxis Supplystation Rf Auxiliary Pyxis Supplystation Rf Auxiliary Firmware Rowa Pouch Packaging Systems Rowa Pouch Packaging Systems Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: BD

Published:

Updated: 2024-09-16T16:42:50.707Z

Reserved: 2022-01-07T00:00:00.000Z

Link: CVE-2022-22767

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-02T14:15:35.843

Modified: 2024-11-21T06:47:24.450

Link: CVE-2022-22767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses