First published: Fri Nov 13 2020(Updated: )
BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authentication process between specified versions of the BD Alaris PC Unit and the BD Alaris Systems Manager. If exploited, an attacker could perform a denial-of-service attack on the BD Alaris PC Unit by modifying the configuration headers of data in transit. A denial-of-service attack could lead to a drop in the wireless capability of the BD Alaris PC Unit, resulting in manual operation of the PC Unit.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Bd Alaris 8015 Pcu Firmware | <=9.33.1 | |
Bd Alaris 8015 Pcu | ||
BD Alaris Systems Manager | <=4.33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25165 is a vulnerability that exists in versions 9.33.1 and earlier of BD Alaris PC Unit Model 8015 and versions 4.33 and earlier of BD Alaris Systems Manager.
CVE-2020-25165 has a severity rating of 7.5, which is classified as high.
CVE-2020-25165 affects BD Alaris PC Unit Model 8015 versions 9.33.1 and earlier.
CVE-2020-25165 affects BD Alaris Systems Manager versions 4.33 and earlier.
At the moment, there are no known fixes for CVE-2020-25165. It is recommended to follow the guidance provided by BD and implement any necessary mitigations.