BD Vulnerabilities in Pyxis Products
Becton, Dickinson and Company (BD) reported use of default credentials not using password aging in Pyxis products, their automated medication dispensing system
Summary
Becton, Dickinson and Company (BD) reported use of default credentials not using password aging in Pyxis products, their automated medication dispensing system
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Becton, Dickinson and Company (BD) have reported that the Pyxis product line have default credentials that are not using password aging. There is no report of this vulnerability being exploited in a clinical setting.
The vulnerability known as CVE-2022-22767 affects BD Pyxis products and has a CVSSv3 score of 8.8. To exploit this vulnerability, an attacker would need to gain access to the default credentials, infiltrate a facility’s network, and gain access to individual devices or servers. An attacker could then gain access to electronic protected health information (ePHI) or other sensitive information.
Remediation advice
Affected organisations should review the CISA Medical Advisory (ICSMA-22-151-01) BD Pyxis and the BD security advisory BD Pyxis Products - Default Credentials and follow the relevant workarounds.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 1 June 2022 3:20 pm