CVE-2022-26394 describes a medium-severity vulnerability in Baxter Spectrum and Sigma Spectrum infusion pumps, specifically within the Wireless Battery Module (WBM). The flaw stems from a lack of mutual authentication between the WBM and the gateway server, enabling a man-in-the-middle attack. This attack, which requires adjacent network access and low complexity, could allow an attacker to modify parameters, disrupting network connectivity and potentially impacting device functionality. While not actively exploited (no KEV entry) and lacking public exploit code, the vulnerability has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20d29, <= 20d32CPE matchmatch criteria | cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:*:*:*:*:*:*:*:* | ||
16CPE matchmatch criteria | cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16:*:*:*:*:*:*:* | ||
16d38CPE matchmatch criteria | cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:16d38:*:*:*:*:*:*:* | ||
17CPE matchmatch criteria | cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17:*:*:*:*:*:*:* | ||
17d19CPE matchmatch criteria | cpe:2.3:o:baxter:spectrum_wireless_battery_module_firmware:17d19:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.