CVE-2022-26388 is a medium-severity vulnerability affecting several models of ELI and BUR Resting Electrocardiographs, including versions 2.6.0 and prior for ELI 380, and earlier versions for ELI 280, ELI 250c, and ELI 150c. This flaw, categorized as a hard-coded password (CWE-259), allows for authentication abuse. With a CVSS score of 6.4, it can be exploited with physical access to the device (AV:P) and has high impacts on confidentiality and integrity, with a low impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Welch Allyn | ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph | >= 0, <= 2.2.0CNA affecteddefault unaffected | |
| Welch Allyn | ELI 250c/BUR 250c Resting Electrocardiograph | >= 0, <= 2.1.2CNA affecteddefault unaffected | |
| Welch Allyn | ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph | >= 0, <= 2.3.1CNA affecteddefault unaffected | |
| Welch Allyn | ELI 380 Resting Electrocardiograph | >= 0, <= 2.6.0CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.