The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:HBd Bodyguard 121 Twins
HWBdall versionsBd Bodyguard 121 Twins Firmware
OSBdall versionsBd Bodyguard 323 Colorvision
HWBdall versionsBd Bodyguard 323 Colorvision Firmware
OSBdall versionsBd Bodyguard 999 603
HWBdall versionsBd Bodyguard 999 603 Firmware
OSBdall versionsBd Bodyguard Duo 999 903
HWBdall versionsBd Bodyguard Duo 999 903 Firmware
OSBdall versionsBd Bodyguard Epidural 999 683
HWBdall versionsBd Bodyguard Epidural 999 683 Firmware
OSBdall versionsBd Bodyguard Pain Manager 999 803
HWBdall versionsBd Bodyguard Pain Manager 999 803 Firmware
OSBdall versionsBd Bodyguard T 999 103
HWBdall versionsBd Bodyguard T 999 103 Firmware
OSBdall versions
Related vulnerabilities
BD Alaris Gateway Workstation — upload złośliwego firmware bez ograniczeń
Auth Bypass w pompach strzykawkowych BD Alaris — nieautoryzowany zdalny dostęp
Hard-coded password w BD PerformA i KLA Journal Service — dostęp do bazy BD Kiestra
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the inst...