MEDIUM🇵🇱 Wersja polska

CVE-2022-43557

CVSS 5.3v3.1pub. 2022-12-05upd. 2024-11-21

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.

CVSS Vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
  • Bd Bodyguard 121 Twins

    HW
    Bd
    all versions
  • Bd Bodyguard 121 Twins Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard 323 Colorvision

    HW
    Bd
    all versions
  • Bd Bodyguard 323 Colorvision Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard 999 603

    HW
    Bd
    all versions
  • Bd Bodyguard 999 603 Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard Duo 999 903

    HW
    Bd
    all versions
  • Bd Bodyguard Duo 999 903 Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard Epidural 999 683

    HW
    Bd
    all versions
  • Bd Bodyguard Epidural 999 683 Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard Pain Manager 999 803

    HW
    Bd
    all versions
  • Bd Bodyguard Pain Manager 999 803 Firmware

    OS
    Bd
    all versions
  • Bd Bodyguard T 999 103

    HW
    Bd
    all versions
  • Bd Bodyguard T 999 103 Firmware

    OS
    Bd
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2019-10959CRITICAL10.0PL ✓same vendor

BD Alaris Gateway Workstation — upload złośliwego firmware bez ograniczeń

CVE-2018-14786CRITICAL9.4PL ✓same vendor

Auth Bypass w pompach strzykawkowych BD Alaris — nieautoryzowany zdalny dostęp

CVE-2017-6022CRITICAL9.8PL ✓same vendor

Hard-coded password w BD PerformA i KLA Journal Service — dostęp do bazy BD Kiestra

CVE-2023-30563HIGH8.2same vendor

A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.

CVE-2022-47376HIGH7.3same vendor

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the inst...