Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-27910 Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.
Fixes

Solution

BD is currently strengthening our credential management capabilities in BD Pyxis™ products. Service personnel are proactively working with customers whose domain-joined server(s) credentials require updates. BD is currently piloting a credential management solution that is initially targeted for only specific BD Pyxis™ product versions and will allow for improved authentication management practices with specific local operating system credentials. Changes needed for installation, upgrade or to applications are being evaluated as part of the overall remediation.


Workaround

Limit physical access to only authorized personnel.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: BD

Published:

Updated: 2024-09-16T16:42:50.707Z

Reserved: 2022-01-07T00:00:00

Link: CVE-2022-22767

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-06-02T14:15:35.843

Modified: 2024-11-21T06:47:24.450

Link: CVE-2022-22767

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.