Skip to main content

BD Alaris Gateway Workstation RCE Vulnerabilities

BD (Becton, Dickinson and Company) has released details of two vulnerabilities in their Alaris Gateway Workstation product.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

BD (Becton, Dickinson and Company) has released details of two vulnerabilities in their Alaris Gateway Workstation product.


Threat details

A remote unauthenticated attacker could exploit these vulnerabilities to execute arbitrary code, alter or remove data, or gain control of an affected system.

The first vulnerability (CVE-2019-10959, CVSS v3 10.0) is a result of Gateway Workstation improperly verifying firmware files during the update process. An attacker with access to the same network as the device can alter these files in order to install unauthorised firmware on the device.

The second vulnerability (CVE-2019-10962, CVSS v3 7.3) lies in the Gateway Workstation web browser interface failing to verify user inputs. A remote attacker can pass malicious inputs to the interface in order to alter status and configuration information.

For further information:


Remediation steps

Type Step

BD have released firmware versions 1.3.2 and 1.6.1 to address CVE-2019-10962 and are assessing software updates to address CVE-2019-10959. Organisations are encouraged to immediately apply these updates as they become available.

They have also recommended several mitigations that organisations may apply:

  • Apply suitable VLAN isolation to ensure Gateway Workstation devices are properly segregated.
  • Disable the SMB protocol if it is not used.

For further remediation guidance, organisations are encouraged to review the following BD notifications and contact their relevant suppliers:



Last edited: 14 February 2020 2:45 pm