Vulnerabilities (CVE)

Filtered by CWE-1299
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-39723 1 Ibm 1 Storage Virtualize 2024-11-21 N/A 4.6 MEDIUM
IBM FlashSystem 5300 USB ports may be usable even if the port has been disabled by the administrator. A user with physical access to the system could use the USB port to cause loss of access to data. IBM X-Force ID: 295935.
CVE-2022-43557 1 Bd 14 Bodyguard 121 Twins, Bodyguard 121 Twins Firmware, Bodyguard 323 Colorvision and 11 more 2024-11-21 N/A 5.3 MEDIUM
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
CVE-2024-47944 2024-10-15 N/A 6.8 MEDIUM
The device directly executes .patch firmware upgrade files on a USB stick without any prior authentication in the admin interface. This leads to an unauthenticated code execution via the firmware upgrade function.