CVE-2022-47376
CVSS 3.1 Score 7.3 of 10 (high)
Details
Summary
CVE-2022-47376 is a vulnerability affecting the Alaris Infusion Central software versions 1.1 to 1.3.2. This issue involves a recoverable password that can be accessed after installation. Although patient health data is not stored in the database, some sites may opt to save personal data, adding a potential privacy risk. This weakness could allow unauthorized users to gain access to the system with administrative privileges, posing a significant threat to system security. It is recommended that users of these affected versions upgrade to the latest patch to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Becton Dickinson