First published: Thu Jun 13 2019(Updated: )
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bd Alaris Gateway Workstation Firmware | =1.0.13 | |
Bd Alaris Gateway Workstation Firmware | =1.1.3-10 | |
Bd Alaris Gateway Workstation Firmware | =1.1.3-11 | |
Bd Alaris Gateway Workstation Firmware | =1.1.5 | |
Bd Alaris Gateway Workstation Firmware | =1.1.6 | |
BD Alaris Gateway Workstation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10962 is a vulnerability in BD Alaris Gateway versions 1.0.13, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.1.5, and 1.1.6 that allows an attacker to gain access to the status and configuration of the Alaris Gateway Workstation terminal.
CVE-2019-10962 has a severity rating of medium with a CVSS score of 5.3.
An attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal can exploit CVE-2019-10962 to gain unauthorized access to its status and configuration.
BD Alaris Gateway versions 1.0.13, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.1.5, and 1.1.6 are affected by CVE-2019-10962.
Yes, the BD Alaris Gateway Workstation firmware versions 1.0.13, 1.1.3-10, 1.1.3-11, 1.1.5, and 1.1.6 are vulnerable to CVE-2019-10962.