CVE-2023-30559

The firmware update package for the wireless card is not properly signed and can be modified.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:bd:alaris_8015_pcu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bd:alaris_8015_pcu:-:*:*:*:*:*:*:*

History

08 Feb 2024, 22:15

Type Values Removed Values Added
CWE CWE-20
CWE-345
Summary (en) The configuration from the PCU can be modified without authentication using physical connection to the PCU. (en) The firmware update package for the wireless card is not properly signed and can be modified.

25 Jul 2023, 18:55

Type Values Removed Values Added
CPE cpe:2.3:o:bd:alaris_8015_pcu_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:bd:alaris_8015_pcu:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.7
CWE CWE-287
References (MISC) https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-guardrails-suite-mx - (MISC) https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-alaris-system-with-guardrails-suite-mx - Vendor Advisory

13 Jul 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-13 18:15

Updated : 2024-02-08 22:15


NVD link : CVE-2023-30559

Mitre link : CVE-2023-30559

CVE.ORG link : CVE-2023-30559


JSON object : View

Products Affected

bd

  • alaris_8015_pcu
  • alaris_8015_pcu_firmware
CWE
CWE-287

Improper Authentication

CWE-20

Improper Input Validation

CWE-345

Insufficient Verification of Data Authenticity