MEDIUM🇵🇱 Wersja polska

CVE-2019-10962

CVSS 5.3v3.1pub. 2019-06-13upd. 2024-11-21

BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
  • Bd Alaris Gateway Workstation

    HW
    Bd
    all versions
  • Bd Alaris Gateway Workstation Firmware

    OS
    Bd
    1.0.131.1.31.1.51.1.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-10959CRITICAL10.0PL ✓same product

BD Alaris Gateway Workstation — upload złośliwego firmware bez ograniczeń

CVE-2018-14786CRITICAL9.4PL ✓same vendor

Auth Bypass w pompach strzykawkowych BD Alaris — nieautoryzowany zdalny dostęp

CVE-2017-6022CRITICAL9.8PL ✓same vendor

Hard-coded password w BD PerformA i KLA Journal Service — dostęp do bazy BD Kiestra

CVE-2023-30563HIGH8.2same vendor

A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.

CVE-2022-47376HIGH7.3same vendor

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the inst...