CVE-2023-30561: Lack of Cryptographic Security of IUI Bus
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-30561?
CVE-2023-30561 is a vulnerability that allows a threat actor with physical access to potentially read or modify data flowing between the BD Alaris 8015 PCU and its modules.
What is the severity of CVE-2023-30561?
CVE-2023-30561 has a severity value of 6.1, which is considered medium.
How does CVE-2023-30561 affect BD Alaris 8015 PCU firmware?
CVE-2023-30561 affects BD Alaris 8015 PCU firmware versions up to and including 12.1.3.
Can the BD Alaris 8015 PCU itself be vulnerable to CVE-2023-30561?
No, the BD Alaris 8015 PCU itself is not vulnerable to CVE-2023-30561.
How can I learn more about CVE-2023-30561?
You can learn more about CVE-2023-30561 by visiting the following reference link: [BD Alaris System with Guardrails Suite MX Security Bulletin](https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-guardrails-suite-mx)