CVE-2024-10476

CVSS 3.1 Score 8.0 of 10 (high)

Details

Published Dec 17, 2024
CWE ID 1392

Summary

CVE-2024-10476 is a vulnerability affecting certain BD Diagnostic Solutions products. The issue involves the use of default credentials, which could allow unauthorized access. If exploited, threat actors can modify, delete data, including sensitive information like PHI and PII. The impact extends to system availability, as attackers may be able to shut down the system. Notably, only BD Synapsys™ Informatics Solution installed on a NUC server is affected by this vulnerability. Instances installed on customer-provided virtual machines or BD Kiestra™ SCU hardware are not within the scope.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share