CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
The data flowing between the PCU and its modules is insecure. A threat actor with physical access could potentially read or modify data by attaching a specially crafted device while an infusion is running. |
The configuration from the PCU can be modified without authentication using physical connection to the PCU.
|
The firmware update package for the wireless card is not properly signed and can be modified. |
1Bd 2Alaris 8015 Pcu Firmware Alaris Systems ManagerJun 17, 2026 Nov 13, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authentication vulnerability within the authen...Show more |