Vulnerability Description
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bd | Alaris 8015 Pcu Firmware | <= 12.1.3 |
| Bd | Alaris 8015 Pcu | - |
Related Weaknesses (CWE)
References
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-gMitigationVendor Advisory
- https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-gMitigationVendor Advisory
FAQ
What is CVE-2023-30561?
CVE-2023-30561 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is run...
How severe is CVE-2023-30561?
CVE-2023-30561 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-30561?
Check the references section above for vendor advisories and patch information. Affected products include: Bd Alaris 8015 Pcu Firmware, Bd Alaris 8015 Pcu.