BD Alaris Plus Medical Pump Vulnerability
A remote attacker could exploit this vulnerability to impact the functionality of affected devices when they are connected to a terminal server using the serial port.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A remote attacker could exploit this vulnerability to impact the functionality of affected devices when they are connected to a terminal server using the serial port.
Affected platforms
The following platforms are known to be affected:
BD Alaris Plus medical syringe pumps
- BD Alaris Plus medical syringe pumps - Version 2.3.6 and earlier (including CC, GH, GS and TIVA Series pumps)
Threat details
Please note that patient identifiable data is not exposed by this vulnerability.
For further information
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 12:38 pm