BD Alaris Gateway Workstation RCE Vulnerabilities
BD (Becton, Dickinson and Company) has released details of two vulnerabilities in their Alaris Gateway Workstation product.
Summary
BD (Becton, Dickinson and Company) has released details of two vulnerabilities in their Alaris Gateway Workstation product.
Threat details
A remote unauthenticated attacker could exploit these vulnerabilities to execute arbitrary code, alter or remove data, or gain control of an affected system.
The first vulnerability (CVE-2019-10959, CVSS v3 10.0) is a result of Gateway Workstation improperly verifying firmware files during the update process. An attacker with access to the same network as the device can alter these files in order to install unauthorised firmware on the device.
The second vulnerability (CVE-2019-10962, CVSS v3 7.3) lies in the Gateway Workstation web browser interface failing to verify user inputs. A remote attacker can pass malicious inputs to the interface in order to alter status and configuration information.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
BD have released firmware versions 1.3.2 and 1.6.1 to address CVE-2019-10962 and are assessing software updates to address CVE-2019-10959. Organisations are encouraged to immediately apply these updates as they become available. They have also recommended several mitigations that organisations may apply:
For further remediation guidance, organisations are encouraged to review the following BD notifications and contact their relevant suppliers:
|
CVE Vulnerabilities
Last edited: 14 February 2020 2:45 pm