CVE Feed

    Dashboard / CVE / CVE-2022-22766

    CVE-2022-22766

    Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.

    Published:Feb 11, 2022
    Last Modified:Nov 21, 2024
    EPS:Feb 11, 2022
    EPSS Score:0.00049
    CVSS Score:7

    Affected Products

    Vendor
    Bd
    Product
    Pyxis Anesthesia Station 4000
    Vendor
    Bd
    Product
    Pyxis Anesthesia Station 4000 Firmware
    Vendor
    Bd
    Product
    Pyxis Anesthesia Station Es
    Vendor
    Bd
    Product
    Pyxis Anesthesia Station Es Firmware
    Vendor
    Bd
    Product
    Pyxis Cato
    Vendor
    Bd
    Product
    Pyxis Cato Firmware
    Vendor
    Bd
    Product
    Pyxis Ciisafe
    Vendor
    Bd
    Product
    Pyxis Ciisafe Firmware
    Vendor
    Bd
    Product
    Pyxis Inventory Connect
    Vendor
    Bd
    Product
    Pyxis Inventory Connect Firmware
    Vendor
    Bd
    Product
    Pyxis Iv Prep
    Vendor
    Bd
    Product
    Pyxis Iv Prep Firmware
    Vendor
    Bd
    Product
    Pyxis Jitrbud
    Vendor
    Bd
    Product
    Pyxis Jitrbud Firmware
    Vendor
    Bd
    Product
    Pyxis Kanban Rf
    Vendor
    Bd
    Product
    Pyxis Kanban Rf Firmware
    Vendor
    Bd
    Product
    Pyxis Logistics
    Vendor
    Bd
    Product
    Pyxis Logistics Firmware
    Vendor
    Bd
    Product
    Pyxis Med Link Family
    Vendor
    Bd
    Product
    Pyxis Med Link Family Firmware
    Vendor
    Bd
    Product
    Pyxis Medbank
    Vendor
    Bd
    Product
    Pyxis Medbank Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation 4000
    Vendor
    Bd
    Product
    Pyxis Medstation 4000 Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation Es
    Vendor
    Bd
    Product
    Pyxis Medstation Es Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation Es Server
    Vendor
    Bd
    Product
    Pyxis Medstation Es Server Firmware
    Vendor
    Bd
    Product
    Pyxis Parassist
    Vendor
    Bd
    Product
    Pyxis Parassist Firmware
    Vendor
    Bd
    Product
    Pyxis Pharmopack
    Vendor
    Bd
    Product
    Pyxis Pharmopack Firmware
    Vendor
    Bd
    Product
    Pyxis Procedurestation
    Vendor
    Bd
    Product
    Pyxis Procedurestation Firmware
    Vendor
    Bd
    Product
    Pyxis Rapid Rx
    Vendor
    Bd
    Product
    Pyxis Rapid Rx Firmware
    Vendor
    Bd
    Product
    Pyxis Stockstation
    Vendor
    Bd
    Product
    Pyxis Stockstation Firmware
    Vendor
    Bd
    Product
    Pyxis Supplycenter
    Vendor
    Bd
    Product
    Pyxis Supplycenter Firmware
    Vendor
    Bd
    Product
    Pyxis Supplyroller
    Vendor
    Bd
    Product
    Pyxis Supplyroller Firmware
    Vendor
    Bd
    Product
    Pyxis Supplystation
    Vendor
    Bd
    Product
    Pyxis Supplystation Firmware
    Vendor
    Bd
    Product
    Pyxis Track And Deliver
    Vendor
    Bd
    Product
    Pyxis Track And Deliver Firmware
    Vendor
    Bd
    Product
    Rowa Pouch Packaging Systems
    Vendor
    Bd
    Product
    Rowa Pouch Packaging Systems Firmware

    Exploits

    No exploit reference

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High