CVE-2019-10959
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS, Alaris GH, Alaris CC, Alaris TIVA, The application does not restrict the upload of malicious files during a firmware update.
- CVSS 3.0
- 10.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 2.53% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- bd/alaris gateway workstation firmware · bd/alaris gs syringe pump firmware · bd/alaris gh syringe pump firmware · bd/alaris cc syringe pump firmware · bd/alaris tiva syringe pump firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/108765Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-164-01Mitigation, Third Party Advisory, US Government Resource
- https://www.bd.com/en-us/support/product-security-and-privacy/product-security-bulletins/alaris-gateway-workstation-unauthorized-firmwareVendor Advisory
- http://www.securityfocus.com/bid/108765Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-164-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.