VulnerabilityModified
CVE-2022-43557
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface.
MEDIUM 5.3EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1299, CWE-287
- Affected
- bd/bodyguard 999-603 firmware · bd/bodyguard duo 999-903 firmware · bd/bodyguard epidural 999-683 firmware · bd/bodyguard pain manager 999-803 firmware · bd/bodyguard t 999-103 firmware · bd/bodyguard 323 colorvision firmware · bd/bodyguard 121 twins firmware
- Source
- cybersecurity@bd.com
References
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-bodyguard-pumps-rs-232-interface-vulnerabilityMitigation, Vendor Advisory
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-bodyguard-pumps-rs-232-interface-vulnerabilityMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.