Show plain JSON{"containers": {"cna": {"affected": [{"product": "Baxter Spectrum Wireless Battery Module (WBM)", "vendor": "Baxter", "versions": [{"status": "affected", "version": "16"}, {"status": "affected", "version": "16D38"}, {"status": "affected", "version": "17"}, {"status": "affected", "version": "17D19"}, {"status": "affected", "version": "20D29"}, {"status": "affected", "version": "20D30"}, {"status": "affected", "version": "20D31"}, {"status": "affected", "version": "20D32"}, {"status": "affected", "version": "22D19"}, {"status": "affected", "version": "22D20"}, {"status": "affected", "version": "22D21"}, {"status": "affected", "version": "22D22"}, {"status": "affected", "version": "22D23"}, {"status": "affected", "version": "22D24"}, {"status": "affected", "version": "22D25"}, {"status": "affected", "version": "22D26"}, {"status": "affected", "version": "22D27"}, {"status": "affected", "version": "22D28"}]}], "datePublic": "2022-09-08T00:00:00", "descriptions": [{"lang": "en", "value": "The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information."}], "metrics": [{"cvssV3_1": {"attackComplexity": "HIGH", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 4.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}}], "problemTypes": [{"descriptions": [{"cweId": "CWE-311", "description": "CWE-311 Missing Encryption of Sensitive Data", "lang": "en", "type": "CWE"}]}], "providerMetadata": {"dateUpdated": "2022-09-09T14:40:06", "orgId": "dba971b9-eb30-4121-91e1-3b45611354aa", "shortName": "Baxter"}, "references": [{"tags": ["x_refsource_MISC"], "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"}], "source": {"discovery": "EXTERNAL"}, "title": "Unencrypted internal storage of security credentials", "x_generator": {"engine": "Vulnogram 0.0.9"}, "x_legacyV4Record": {"CVE_data_meta": {"ASSIGNER": "productsecurity@baxter.com", "DATE_PUBLIC": "2022-09-08T22:03:00.000Z", "ID": "CVE-2022-26390", "STATE": "PUBLIC", "TITLE": "Unencrypted internal storage of security credentials"}, "affects": {"vendor": {"vendor_data": [{"product": {"product_data": [{"product_name": "Baxter Spectrum Wireless Battery Module (WBM)", "version": {"version_data": [{"version_affected": "=", "version_name": "16", "version_value": ""}, {"version_affected": "=", "version_name": "16D38", "version_value": ""}, {"version_affected": "=", "version_name": "17", "version_value": ""}, {"version_affected": "=", "version_name": "17D19", "version_value": ""}, {"version_affected": "=", "version_name": "20D29", "version_value": ""}, {"version_affected": "=", "version_name": "20D30", "version_value": ""}, {"version_affected": "=", "version_name": "20D31", "version_value": ""}, {"version_affected": "=", "version_name": "20D32", "version_value": ""}, {"version_affected": "=", "version_name": "22D19", "version_value": ""}, {"version_affected": "=", "version_name": "22D20", "version_value": ""}, {"version_affected": "=", "version_name": "22D21", "version_value": ""}, {"version_affected": "=", "version_name": "22D22", "version_value": ""}, {"version_affected": "=", "version_name": "22D23", "version_value": ""}, {"version_affected": "=", "version_name": "22D24", "version_value": ""}, {"version_affected": "=", "version_name": "22D25", "version_value": ""}, {"version_affected": "=", "version_name": "22D26", "version_value": ""}, {"version_affected": "=", "version_name": "22D27", "version_value": ""}, {"version_affected": "=", "version_name": "22D28", "version_value": ""}]}}]}, "vendor_name": "Baxter"}]}}, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": {"description_data": [{"lang": "eng", "value": "The Baxter Spectrum Wireless Battery Module (WBM) stores network credentials and PHI (only applicable to Spectrum IQ pumps using auto programming) in unencrypted form. An attacker with physical access to a device that hasn't had all data and settings erased may be able to extract sensitive information."}]}, "generator": {"engine": "Vulnogram 0.0.9"}, "impact": {"cvss": {"attackComplexity": "HIGH", "attackVector": "PHYSICAL", "availabilityImpact": "NONE", "baseScore": 4.2, "baseSeverity": "MEDIUM", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N", "version": "3.1"}}, "problemtype": {"problemtype_data": [{"description": [{"lang": "eng", "value": "CWE-311 Missing Encryption of Sensitive Data"}]}]}, "references": {"reference_data": [{"name": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx", "refsource": "MISC", "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"}]}, "source": {"discovery": "EXTERNAL"}}}, "adp": [{"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T05:03:32.877Z"}, "title": "CVE Program Container", "references": [{"tags": ["x_refsource_MISC", "x_transferred"], "url": "https://www.us-cert.gov/ics/advisories/icsma-22-xxx-xx"}]}]}, "cveMetadata": {"assignerOrgId": "dba971b9-eb30-4121-91e1-3b45611354aa", "assignerShortName": "Baxter", "cveId": "CVE-2022-26390", "datePublished": "2022-09-09T14:40:06.351985Z", "dateReserved": "2022-03-03T00:00:00", "dateUpdated": "2024-09-17T04:09:45.443Z", "state": "PUBLISHED"}, "dataType": "CVE_RECORD", "dataVersion": "5.1"}