VYPR
Vendor

BDCOM

Products
9
CVEs
13
Across products
15
Status
Private

Products

9

Recent CVEs

13
  • CVE-2023-30563HigJul 13, 2023
    risk 0.53cvss 8.2epss 0.00

    A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.

  • CVE-2025-1546HigFeb 21, 2025
    risk 0.48cvss 7.3epss 0.03

    A vulnerability has been found in BDCOM Behavior Management and Auditing System up to 20250210 and classified as critical. Affected by this vulnerability is the function log_operate_clear of the file /webui/modules/log/operate.mds. The manipulation of the argument start_code…

  • CVE-2022-47376HigJun 13, 2023
    risk 0.47cvss 7.3epss 0.00

    The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.

  • CVE-2023-30562MedJul 13, 2023
    risk 0.44cvss 6.7epss 0.00

    A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.

  • CVE-2023-30560MedJul 13, 2023
    risk 0.44cvss 6.8epss 0.00

    The configuration from the PCU can be modified without authentication using physical connection to the PCU.

  • CVE-2023-39678MedAug 29, 2023
    risk 0.40cvss 6.1epss 0.00

    A cross-site scripting (XSS) vulnerability in the device web interface (Log Query page) of BDCOM OLT P3310D-2AC 10.1.0F Build 69083 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.

  • CVE-2023-30561MedJul 13, 2023
    risk 0.40cvss 6.1epss 0.00

    The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.

  • CVE-2023-0659MedFeb 3, 2023
    risk 0.35cvss 5.3epss 0.01

    A vulnerability was found in BDCOM 1704-WGL 2.0.6314. It has been classified as critical. This affects an unknown part of the file /param.file.tgz of the component Backup File Handler. The manipulation leads to information disclosure. It is possible to initiate the attack…

  • CVE-2023-29065MedNov 28, 2023
    risk 0.27cvss 4.1epss 0.00

    The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or destroy data stored in the database.

  • CVE-2026-6998LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A vulnerability was detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. Affected is an unknown function of the component New RMON Statistics Page. The manipulation of the argument Owner results in cross site scripting. The attack can be executed remotely. The exploit is now…

  • CVE-2026-6997LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A security vulnerability has been detected in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This impacts an unknown function of the component New RMON History Page. The manipulation of the argument Owner leads to cross site scripting. Remote exploitation of the attack is possible. The…

  • CVE-2026-6996LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A weakness has been identified in BDCOM P3310D 0.4.2 10.1.0F Build 86345. This affects an unknown function of the component rmon event Tab. Executing a manipulation of the argument Description can lead to cross site scripting. The attack may be launched remotely. The exploit has…

  • CVE-2026-6995LowApr 25, 2026
    risk 0.16cvss 2.4epss 0.00

    A security flaw has been discovered in BDCOM P3310D 0.4.2 10.1.0F Build 86345. The impacted element is an unknown function of the file /index.asp of the component New User Page. Performing a manipulation of the argument User name results in cross site scripting. The attack may…