SB2022060111 - Not Using Password Aging in BD Pyxis
Published: June 1, 2022
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Not Using Password Aging (CVE-ID: CVE-2022-22767)
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to the affected products are installed with default credentials and may still operate with these credentials. A remote attacker on the local network can gain privileged access to the underlying file system and gain access to ePHI or other sensitive information.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.