Lucene search

K
cveIcscertCVE-2019-10962
HistoryJun 13, 2019 - 9:29 p.m.

CVE-2019-10962

2019-06-1321:29:15
CWE-284
icscert
web.nvd.nist.gov
73
cve-2019-10962
alaris gateway
web browser
ui
vulnerability
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

32.0%

BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.

Affected configurations

Nvd
Node
bdalaris_gateway_workstation_firmwareMatch1.0.13
OR
bdalaris_gateway_workstation_firmwareMatch1.1.310
OR
bdalaris_gateway_workstation_firmwareMatch1.1.311
OR
bdalaris_gateway_workstation_firmwareMatch1.1.5
OR
bdalaris_gateway_workstation_firmwareMatch1.1.6
AND
bdalaris_gateway_workstationMatch-
VendorProductVersionCPE
bdalaris_gateway_workstation_firmware1.0.13cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.0.13:*:*:*:*:*:*:*
bdalaris_gateway_workstation_firmware1.1.3cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.3:10:*:*:*:*:*:*
bdalaris_gateway_workstation_firmware1.1.3cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.3:11:*:*:*:*:*:*
bdalaris_gateway_workstation_firmware1.1.5cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.5:*:*:*:*:*:*:*
bdalaris_gateway_workstation_firmware1.1.6cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.6:*:*:*:*:*:*:*
bdalaris_gateway_workstation-cpe:2.3:h:bd:alaris_gateway_workstation:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "BD Alaris Gateway Workstation",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "versions 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5,1.1.6"
      }
    ]
  }
]

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

5.3

Confidence

High

EPSS

0.001

Percentile

32.0%

Related for CVE-2019-10962