Skip to main content

BD Alaris PCU DoS Vulnerability

BD (Becton, Dickinson and Co.) has released details of an uncontrolled resource consumption vulnerability (CWE-400) affecting their Alaris Point-of-Care Unit (PCU) infusion delivery system. They claim that a remote unauthenticated attacker could cause a denial-of-service (DoS) condition on an affected device.

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

BD (Becton, Dickinson and Co.) has released details of an uncontrolled resource consumption vulnerability (CWE-400) affecting their Alaris Point-of-Care Unit (PCU) infusion delivery system. They claim that a remote unauthenticated attacker could cause a denial-of-service (DoS) condition on an affected device.


Affected platforms

The following platforms are known to be affected:

  • BD Alaris PCU - Versions 9.13, 9.19, 9.33, and 12.1

Threat details

The vulnerability is a result of a hard-coded maximum segment size (MSS) overflow in the Linux kernel used by Alaris PCUs embedded wireless network module (Laird WB40NBT). By default, the kernel uses a 48 byte MSS, which a remote user can exploit to fragment any TCP retransmission queues more often than if a larger MSS were used. This can result in the kernel allocating more resources than are available to the networking module, resulting in the kernel crashing.

For further information:


Remediation steps

Type Step

As this vulnerability is the result of a had-coded fault in a component outside their full control, BD has advised that they are not producing any updates to address this vulnerability in affected devices.

However, they have recommended the following mitigating controls be applied by affected organisations:

  • Ensure all Alaris PCUs and Alaris Systems Manager products be separated by a suitable firewall.
  • Consider applying stronger wireless authentication protocols where possible.

For further information please review BD's security bulletin.



CVE Vulnerabilities

Last edited: 29 June 2021 12:01 pm