BD Alaris PCU DoS Vulnerability
BD (Becton, Dickinson and Co.) has released details of an uncontrolled resource consumption vulnerability (CWE-400) affecting their Alaris Point-of-Care Unit (PCU) infusion delivery system. They claim that a remote unauthenticated attacker could cause a denial-of-service (DoS) condition on an affected device.
Summary
BD (Becton, Dickinson and Co.) has released details of an uncontrolled resource consumption vulnerability (CWE-400) affecting their Alaris Point-of-Care Unit (PCU) infusion delivery system. They claim that a remote unauthenticated attacker could cause a denial-of-service (DoS) condition on an affected device.
Affected platforms
The following platforms are known to be affected:
- BD Alaris PCU - Versions 9.13, 9.19, 9.33, and 12.1
Threat details
The vulnerability is a result of a hard-coded maximum segment size (MSS) overflow in the Linux kernel used by Alaris PCUs embedded wireless network module (Laird WB40NBT). By default, the kernel uses a 48 byte MSS, which a remote user can exploit to fragment any TCP retransmission queues more often than if a larger MSS were used. This can result in the kernel allocating more resources than are available to the networking module, resulting in the kernel crashing.
For further information:
Remediation steps
| Type | Step |
|---|---|
|
As this vulnerability is the result of a had-coded fault in a component outside their full control, BD has advised that they are not producing any updates to address this vulnerability in affected devices. However, they have recommended the following mitigating controls be applied by affected organisations:
For further information please review BD's security bulletin. |
CVE Vulnerabilities
Last edited: 29 June 2021 12:01 pm