Vulnerability CVE-2019-10962


Published: 2019-06-13

Description:
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.

Type:

CWE-284

(Improper Access Control)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
BD -> Alaris gateway workstation firmware 

 References:
http://www.securityfocus.com/bid/108763
https://ics-cert.us-cert.gov/advisories/ICSMA-19-164-01

Copyright 2024, cxsecurity.com

 

Back to Top