Skip to main content

BD Pyxis ES Session Fixation Vulnerability

Becton, Dickinson and Company (BD) has released details of a session fixation vulnerability affecting their Pyxis ES platform.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Becton, Dickinson and Company (BD) has released details of a session fixation vulnerability affecting their Pyxis ES platform.


Threat details

An unauthenticated attacker could exploit this vulnerability to acquire the Active Directory credentials of a previous user.

The vulnerability is a result of the system does not coordinate the restriction of existing privileges with Active Directory account changes or expiration. A user on the same Active Directory domain could acquire a previously authenticated user's access credentials, at which point they would have access to the same systems as the previous user.

For further information:


Remediation steps

Type Step

BD have confirmed that this vulnerability has been addressed in the latest release of Pyxis ES, version 1.6.1.1. Organisations are encouraged to contact their relevant suppliers to apply this update immediately.

Alternatively, BD have suggested the following mitigation steps for organisations unable to apply the update:

  • Place Pyxis ES systems on a separate Active Directory domain to their primary domain.
  • Ensure expired Active Directory user accounts are removed from all Pyxis ES related roles.


CVE Vulnerabilities

Last edited: 14 February 2020 2:56 pm