Skip to main content

BD Alaris Vulnerability

Becton, Dickinson and Company (BD) reported a credential management error vulnerability affecting Alaris Infusion Central

Report a cyber attack: call 0300 303 5222 or email [email protected]

Summary

Becton, Dickinson and Company (BD) reported a credential management error vulnerability affecting Alaris Infusion Central


Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

Becton, Dickinson and Company (BD) have reported a vulnerability in Alaris Infusion Central, caused by credential management errors.

CVE-2022-47376 has a CVSSv3 base score of 7.3 and relates to credential management errors. Successful exploitation of this vulnerability could allow an attacker to obtain the database installation password and gain access to the Alaris Infusion Central database, resulting in disclosure of resident personal data. Patient health data is not stored in the database, although some side installations may choose to store personal data. 


Remediation advice

Affected organisations should read relevant CISA advisories ICSMA-23-047-01 and BD Bulletins.

BD recommends the following mitigations and compensating controls to reduce risk associated with this vulnerability: 

  • Change passwords periodically per best security practice. 
  • Ensure physical access controls are in place; only authorised administrators should have access to the Alaris Infusion Central server. 


Last edited: 23 February 2023 4:32 pm