SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-26393

An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.

HIGH 8.1EPSS 0.66%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.66%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

The Baxter Spectrum WBM is susceptible to format string attacks via application messaging. An attacker could use this to read memory in the WBM to access sensitive information or cause a Denial of Service (DoS) on the WBM.

CVSS 3.1
8.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
EPSS
0.66% probability · 50th percentile
CISA KEV
Not listed
Weakness
CWE-134
Affected
baxter/spectrum wireless battery module firmware · baxter/sigma spectrum 35700bax firmware · baxter/sigma spectrum 35700bax2 firmware · baxter/baxter spectrum iq 35700bax3 firmware
Source
productsecurity@baxter.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.