CVE-2023-30565
3.5
Vector
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD
Description
An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.
Affected (1)
Products: Bd: Guardrails Cqi Reporter
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.17 |
Related CWEs
CWE-319
Cleartext Transmission of Sensitive Information
The product transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
The product establishes a communication channel with an endpoint and receives a message from that endpoint, but it does not sufficiently ensure that the message was not modified during transmission.
References (2)
Source: cybersecurity@bd.com
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.