CVE-2022-22766 - CVE House
Back to Database
Status published High CVE-2022-22766

BD Pyxis Products - Hardcoded Credentials

Vulnerability Description

Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health information (ePHI) or other sensitive information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-22766

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Becton Dickinson (BD)

View all reports →

Affected Software

BD Pyxis Anesthesia Station ES, BD Pyxis Anesthesia Station 4000, BD Pyxis CATO, BD Pyxis CIISafe, BD Pyxis Inventory Connect, BD Pyxis IV Prep, BD Pyxis JITrBUD, BD Pyxis KanBan RF, BD Pyxis Logistics, BD Pyxis Med Link Family, BD Pyxis MedBank, BD Pyxis MedStation 4000, BD Pyxis MedStation ES, BD Pyxis MedStation ES Server, BD Pyxis ParAssist, BD Pyxis PharmoPack, BD Pyxis ProcedureStation (including EC), BD Pyxis Rapid Rx, BD Pyxis StockStation, BD Pyxis SupplyCenter, BD Pyxis SupplyRoller, BD Pyxis SupplyStation (including RF, EC, CP), BD Pyxis Track and Deliver, BD Rowa Pouch Packaging Systems
Vulnerable Versions:
All

Timeline

Official Publish: February 11th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)