CVE-2019-6517
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Professional Operating System US release does not properly enforce user access…
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Professional Operating System US release does not properly enforce user access control to privileged accounts, which may allow for unauthorized access to administrative level functions.
- CVSS 3.1
- 6.8 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- bd/facslyric · bd/facslyric ivd
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/106766Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-029-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/106766Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSMA-19-029-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.