VYPR

Spectrum Wireless Battery Module (WBM)

by Baxter

CVEs (5)

  • CVE-2014-5432CriMar 26, 2019
    risk 0.64cvss 9.8epss 0.03

    Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module (WBM) version 16 is remotely accessible via Port 22/SSH without authentication. A remote attacker may be able to make unauthorized configuration changes to the WBM, as well as issue…

  • CVE-2022-26394MedSep 9, 2022
    risk 0.36cvss 5.5epss 0.00

    The Baxter Spectrum WBM does not perform mutual authentication with the gateway server host. This may allow an attacker to perform a man in the middle attack that modifies parameters making the network connection fail.

  • CVE-2022-26393MedSep 9, 2022
    risk 0.33cvss 5.0epss 0.01

    The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.

  • CVE-2022-26390MedSep 9, 2022
    risk 0.27cvss 4.2epss 0.00

    The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to…

  • CVE-2022-26392LowSep 9, 2022
    risk 0.20cvss 3.1epss 0.01

    The Baxter Spectrum WBM (v16, v16D38) and Baxter Spectrum WBM (v17, v17D19, v20D29 to v20D32) when in superuser mode is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information.