bd-alaris-system-with-guardrails-suite-mx
by BDCOM
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30563 | Hig | 0.53 | 8.2 | 0.00 | Jul 13, 2023 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | ||
| CVE-2023-30562 | Med | 0.44 | 6.7 | 0.00 | Jul 13, 2023 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. | ||
| CVE-2023-30560 | Med | 0.44 | 6.8 | 0.00 | Jul 13, 2023 | The configuration from the PCU can be modified without authentication using physical connection to the PCU. | ||
| CVE-2023-30561 | Med | 0.40 | 6.1 | 0.00 | Jul 13, 2023 | The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running. |
- risk 0.53cvss 8.2epss 0.00
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
- risk 0.44cvss 6.7epss 0.00
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
- risk 0.44cvss 6.8epss 0.00
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
- risk 0.40cvss 6.1epss 0.00
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.