CVE Feed

    Dashboard / CVE / CVE-2022-22767

    CVE-2022-22767

    Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product types. If exploited, threat actors may be able to gain privileged access to the underlying file system and could potentially exploit or gain access to ePHI or other sensitive information.

    Published:Jun 1, 2022
    Last Modified:Nov 21, 2024
    EPS:Jun 1, 2022
    EPSS Score:0.00229
    CVSS Score:8.8

    Affected Products

    Vendor
    Bd
    Product
    Pyxis Anesthesia Station Es
    Vendor
    Bd
    Product
    Pyxis Anesthesia Station Es Firmware
    Vendor
    Bd
    Product
    Pyxis Ciisafe
    Vendor
    Bd
    Product
    Pyxis Ciisafe Firmware
    Vendor
    Bd
    Product
    Pyxis Logistics
    Vendor
    Bd
    Product
    Pyxis Logistics Firmware
    Vendor
    Bd
    Product
    Pyxis Medbank
    Vendor
    Bd
    Product
    Pyxis Medbank Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation 4000
    Vendor
    Bd
    Product
    Pyxis Medstation 4000 Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation Es
    Vendor
    Bd
    Product
    Pyxis Medstation Es Firmware
    Vendor
    Bd
    Product
    Pyxis Medstation Es Server
    Vendor
    Bd
    Product
    Pyxis Medstation Es Server Firmware
    Vendor
    Bd
    Product
    Pyxis Parassist
    Vendor
    Bd
    Product
    Pyxis Parassist Firmware
    Vendor
    Bd
    Product
    Pyxis Rapid Rx
    Vendor
    Bd
    Product
    Pyxis Rapid Rx Firmware
    Vendor
    Bd
    Product
    Pyxis Stockstation
    Vendor
    Bd
    Product
    Pyxis Stockstation Firmware
    Vendor
    Bd
    Product
    Pyxis Supplycenter
    Vendor
    Bd
    Product
    Pyxis Supplycenter Firmware
    Vendor
    Bd
    Product
    Pyxis Supplyroller
    Vendor
    Bd
    Product
    Pyxis Supplyroller Firmware
    Vendor
    Bd
    Product
    Pyxis Supplystation
    Vendor
    Bd
    Product
    Pyxis Supplystation Ec
    Vendor
    Bd
    Product
    Pyxis Supplystation Ec Firmware
    Vendor
    Bd
    Product
    Pyxis Supplystation Firmware
    Vendor
    Bd
    Product
    Pyxis Supplystation Rf Auxiliary
    Vendor
    Bd
    Product
    Pyxis Supplystation Rf Auxiliary Firmware
    Vendor
    Bd
    Product
    Rowa Pouch Packaging Systems
    Vendor
    Bd
    Product
    Rowa Pouch Packaging Systems Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High