BD Pyxis ES Session Fixation Vulnerability
Becton, Dickinson and Company (BD) has released details of a session fixation vulnerability affecting their Pyxis ES platform.
Summary
Becton, Dickinson and Company (BD) has released details of a session fixation vulnerability affecting their Pyxis ES platform.
Threat details
An unauthenticated attacker could exploit this vulnerability to acquire the Active Directory credentials of a previous user.
The vulnerability is a result of the system does not coordinate the restriction of existing privileges with Active Directory account changes or expiration. A user on the same Active Directory domain could acquire a previously authenticated user's access credentials, at which point they would have access to the same systems as the previous user.
For further information:
Remediation steps
CVE Vulnerabilities
Last edited: 14 February 2020 2:56 pm