CVE-2022-47376: High severity bd alaris infusion central vulnerability
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-47376?
CVE-2022-47376 is a vulnerability in the Alaris Infusion Central software versions 1.1 to 1.3.2 that may contain a recoverable password after installation.
What is the severity of CVE-2022-47376?
The severity of CVE-2022-47376 is high, with a CVSS score of 7.3.
What software versions are affected by CVE-2022-47376?
The Alaris Infusion Central software versions 1.1 to 1.3.2 are affected by CVE-2022-47376.
Is patient health data stored in the database?
No, no patient health data is stored in the database.
Are personal data stored in the database?
Some site installations may choose to store personal data.
How can I fix CVE-2022-47376?
To fix CVE-2022-47376, update the Alaris Infusion Central software to a version higher than 1.3.2.
Where can I find more information about CVE-2022-47376?
You can find more information about CVE-2022-47376 at the following link: https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/alaris-infusion-central-recoverable-password-vulnerability
What is CWE-522?
CWE-522 is a weakness in the Alaris Infusion Central software that allows a recoverable password after installation.
What is CWE-257?
CWE-257 is a weakness in the Alaris Infusion Central software that allows environmental variables to be overwritten or modified.