CVE-2022-47376

CVSS 3.1 Score 7.3 of 10 (high)

Details

Published Jun 13, 2023
Updated: Jan 3, 2025
CWE ID 522
CWE ID 257

Summary

CVE-2022-47376 is a vulnerability affecting the Alaris Infusion Central software versions 1.1 to 1.3.2. This issue involves a recoverable password that can be accessed after installation. Although patient health data is not stored in the database, some sites may opt to save personal data, adding a potential privacy risk. This weakness could allow unauthorized users to gain access to the system with administrative privileges, posing a significant threat to system security. It is recommended that users of these affected versions upgrade to the latest patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share