Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-10962


BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.


Published

2019-06-13T21:29:15.877

Last Modified

2024-11-21T04:20:15.143

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System bd alaris_gateway_workstation_firmware 1.0.13 Yes
Operating System bd alaris_gateway_workstation_firmware 1.1.3 Yes
Operating System bd alaris_gateway_workstation_firmware 1.1.3 Yes
Operating System bd alaris_gateway_workstation_firmware 1.1.5 Yes
Operating System bd alaris_gateway_workstation_firmware 1.1.6 Yes
Hardware bd alaris_gateway_workstation - No

References