CVE-2023-30565: CQI Data Sniffing
Published Jul 13, 2023
·Updated
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
Affected Software
1 affected component
BD Guardrails Cqi Reporter<=10.17
Remediation
Information
BD recommends customers update to the BD Alarisâ„¢ System v12.3, where available based on regulatory authorization. Customers who require software updates should contact their BD Account Executive to assist with scheduling the remediation.
Event History
Jul 13, 2023
CVE Published
via MITRE·07:06 PM
Data Sourced
via MITRE·07:06 PM
RemedyDescriptionSeverityWeakness
Data Sourced
08:15 PM
Description
Frequently Asked Questions
1
What is CVE-2023-30565?
CVE-2023-30565 is a vulnerability that allows an attacker to sniff infusion data by exploiting an insecure connection between Systems Manager and CQI Reporter application.
2
What is the severity of CVE-2023-30565?
The severity of CVE-2023-30565 is low with a CVSS score of 3.5.
3
Which software is affected by CVE-2023-30565?
The Bd Guardrails Cqi Reporter application version up to 10.17 is affected by CVE-2023-30565.
4
How can I fix CVE-2023-30565?
To fix CVE-2023-30565, apply the necessary patches or updates provided by the vendor.
5
Where can I find more information about CVE-2023-30565?
You can find more information about CVE-2023-30565 in the [BD Cybersecurity Bulletin](https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-guardrails-suite-mx).