BD Alaris Vulnerability
Becton, Dickinson and Company (BD) reported a credential management error vulnerability affecting Alaris Infusion Central
Summary
Becton, Dickinson and Company (BD) reported a credential management error vulnerability affecting Alaris Infusion Central
Affected platforms
The following platforms are known to be affected:
Threat details
Introduction
Becton, Dickinson and Company (BD) have reported a vulnerability in Alaris Infusion Central, caused by credential management errors.
CVE-2022-47376 has a CVSSv3 base score of 7.3 and relates to credential management errors. Successful exploitation of this vulnerability could allow an attacker to obtain the database installation password and gain access to the Alaris Infusion Central database, resulting in disclosure of resident personal data. Patient health data is not stored in the database, although some side installations may choose to store personal data.
Remediation advice
Affected organisations should read relevant CISA advisories ICSMA-23-047-01 and BD Bulletins.
BD recommends the following mitigations and compensating controls to reduce risk associated with this vulnerability:
- Change passwords periodically per best security practice.
- Ensure physical access controls are in place; only authorised administrators should have access to the Alaris Infusion Central server.
Definitive source of threat updates
CVE Vulnerabilities
Last edited: 23 February 2023 4:32 pm