CVE-2019-10962
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation…
Does this matter?
Lower severity and a low EPSS score (1.68%). Track it; it rarely justifies an emergency change on its own.
Description
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.68% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- bd/alaris gateway workstation firmware
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/108763Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-164-01Mitigation, Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/108763Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-164-01Mitigation, Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.