BDCOM
Products
9- 4 CVEs
- 4 CVEs
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
- 1 CVE
Recent CVEs
13| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30563 | Hig | 0.53 | 8.2 | 0.00 | Jul 13, 2023 | A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | ||
| CVE-2025-1546 | Hig | 0.48 | 7.3 | 0.03 | Feb 21, 2025 | A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code… | ||
| CVE-2022-47376 | Hig | 0.47 | 7.3 | 0.00 | Jun 13, 2023 | The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data. | ||
| CVE-2023-30562 | Med | 0.44 | 6.7 | 0.00 | Jul 13, 2023 | A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs. | ||
| CVE-2023-30560 | Med | 0.44 | 6.8 | 0.00 | Jul 13, 2023 | The configuration from the PCU can be modified without authentication using physical connection to the PCU. | ||
| CVE-2023-39678 | Med | 0.40 | 6.1 | 0.00 | Aug 29, 2023 | A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter. | ||
| CVE-2023-30561 | Med | 0.40 | 6.1 | 0.00 | Jul 13, 2023 | The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running. | ||
| CVE-2023-0659 | Med | 0.35 | 5.3 | 0.01 | Feb 3, 2023 | A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack… | ||
| CVE-2023-29065 | Med | 0.27 | 4.1 | 0.00 | Nov 28, 2023 | The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database. | ||
| CVE-2026-6998 | Low | 0.16 | 2.4 | 0.00 | Apr 25, 2026 | A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now… | ||
| CVE-2026-6997 | Low | 0.16 | 2.4 | 0.00 | Apr 25, 2026 | A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The… | ||
| CVE-2026-6996 | Low | 0.16 | 2.4 | 0.00 | Apr 25, 2026 | A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has… | ||
| CVE-2026-6995 | Low | 0.16 | 2.4 | 0.00 | Apr 25, 2026 | A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may… |
- risk 0.53cvss 8.2epss 0.00
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
- risk 0.48cvss 7.3epss 0.03
A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code…
- risk 0.47cvss 7.3epss 0.00
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
- risk 0.44cvss 6.7epss 0.00
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
- risk 0.44cvss 6.8epss 0.00
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
- risk 0.40cvss 6.1epss 0.00
A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
- risk 0.40cvss 6.1epss 0.00
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
- risk 0.35cvss 5.3epss 0.01
A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack…
- risk 0.27cvss 4.1epss 0.00
The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.
- risk 0.16cvss 2.4epss 0.00
A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now…
- risk 0.16cvss 2.4epss 0.00
A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The…
- risk 0.16cvss 2.4epss 0.00
A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has…
- risk 0.16cvss 2.4epss 0.00
A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may…