PT-2019-12104 · Bd · Bd Alaris Gateway
Published
2019-06-13
·
Updated
2020-10-02
·
CVE-2019-10962
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
BD Alaris Gateway versions 1.0.13, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.1.5, and 1.1.6
Description
The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal from gaining access to the status and configuration information of the device.
Recommendations
For BD Alaris Gateway version 1.0.13, update to a version that addresses this issue.
For BD Alaris Gateway version 1.1.3 Build 10, update to a version that addresses this issue.
For BD Alaris Gateway version 1.1.3 MR Build 11, update to a version that addresses this issue.
For BD Alaris Gateway version 1.1.5, update to a version that addresses this issue.
For BD Alaris Gateway version 1.1.6, update to a version that addresses this issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bd Alaris Gateway