Risk | Low |
Patch available | NO |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2022-43557 |
CWE-ID | CWE-1299 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
BD BodyGuard Hardware solutions / Medical equipment CME BodyGuard 323 (2nd Edition) Hardware solutions / Medical equipment CME BodyGuard 323 Color Vision (2nd Edition) Hardware solutions / Medical equipment CME BodyGuard 323 Color Vision (3rd Edition) Hardware solutions / Medical equipment CME BodyGuard Twins (2nd Edition) Hardware solutions / Medical equipment |
Vendor | Becton, Dickinson and Company (BD) |
Security Bulletin
This security bulletin contains one low risk vulnerability.
EUVDB-ID: #VU69825
Risk: Low
CVSSv4.0: 0.7 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-43557
CWE-ID:
CWE-1299 - Missing Protection Mechanism for Alternate Hardware Interface
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to the affected pumps allow for access through the RS-232 (serial) port interface. An attacker with physical access can disable the pump.
MitigationCybersecurity Help is currently unaware of any official solution to address this vulnerability.
Vulnerable software versionsBD BodyGuard: All versions
CME BodyGuard 323 (2nd Edition): All versions
CME BodyGuard 323 Color Vision (2nd Edition): All versions
CME BodyGuard 323 Color Vision (3rd Edition): All versions
CME BodyGuard Twins (2nd Edition): All versions
CPE2.3http://ics-cert.us-cert.gov/advisories/icsma-22-335-01
http://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-bodyguard-pumps-rs-232-interface-vulnerability
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.