CVE-2024-10476: High severity BD Synapsys Informatics Solution vulnerability

Published Dec 17, 2024
·
Updated

Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive information such as protected health information (PHI) and personally identifiable information (PII). Exploitation of this vulnerability may allow an attacker to shut down or otherwise impact the availability of the system. Note: BD Synapsys™ Informatics Solution is only in scope of this vulnerability when installed on a NUC server. BD Synapsys™ Informatics Solution installed on a customer-provided virtual machine or on the BD Kiestra™ SCU hardware is not in scope.

Affected Software

2 affected components
BD Synapsys Informatics Solution
BD Kiestra SCU

Event History

Dec 17, 2024
CVE Published
via MITRE·03:16 PM
Data Sourced
via MITRE·03:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-10476?

CVE-2024-10476 has a high severity rating due to the use of default credentials that can lead to unauthorized access.

2

How do I fix CVE-2024-10476?

To fix CVE-2024-10476, users must immediately change the default credentials for the affected BD Diagnostic Solutions products.

3

What products are affected by CVE-2024-10476?

CVE-2024-10476 affects BD Synapsys Informatics Solution and BD Kiestra SCU.

4

What are the risks associated with CVE-2024-10476?

The risks associated with CVE-2024-10476 include potential unauthorized access, modification, or deletion of sensitive data such as PII and PHI.

5

What types of data could be exposed due to CVE-2024-10476?

CVE-2024-10476 could expose sensitive data, including protected health information (PHI) and personally identifiable information (PII).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203