CVE-2022-47376

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.
Configurations

Configuration 1 (hide)

cpe:2.3:a:bd:alaris_infusion_central:*:*:*:*:*:*:*:*

History

24 Jun 2023, 01:14

Type Values Removed Values Added
CWE CWE-522
First Time Bd alaris Infusion Central
Bd
CPE cpe:2.3:a:bd:alaris_infusion_central:*:*:*:*:*:*:*:*
References (MISC) https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/alaris-infusion-central-recoverable-password-vulnerability - (MISC) https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/alaris-infusion-central-recoverable-password-vulnerability - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

13 Jun 2023, 21:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 20:15

Updated : 2024-02-28 20:13


NVD link : CVE-2022-47376

Mitre link : CVE-2022-47376

CVE.ORG link : CVE-2022-47376


JSON object : View

Products Affected

bd

  • alaris_infusion_central
CWE
CWE-522

Insufficiently Protected Credentials

CWE-257

Storing Passwords in a Recoverable Format