PT-2019-12104 · Bd · Bd Alaris Gateway

Published

2019-06-13

·

Updated

2020-10-02

·

CVE-2019-10962

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions BD Alaris Gateway versions 1.0.13, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.1.5, and 1.1.6
Description The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal from gaining access to the status and configuration information of the device.
Recommendations For BD Alaris Gateway version 1.0.13, update to a version that addresses this issue. For BD Alaris Gateway version 1.1.3 Build 10, update to a version that addresses this issue. For BD Alaris Gateway version 1.1.3 MR Build 11, update to a version that addresses this issue. For BD Alaris Gateway version 1.1.5, update to a version that addresses this issue. For BD Alaris Gateway version 1.1.6, update to a version that addresses this issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-10962

Affected Products

Bd Alaris Gateway