Lucene search

K
cveBDCVE-2022-40263
HistoryNov 04, 2022 - 7:15 p.m.

CVE-2022-40263

2022-11-0419:15:11
CWE-798
BD
web.nvd.nist.gov
42
6
bd totalys multiprocessor
hardcoded credentials
unauthorized access
sensitive information
ephi
phi
pii
vulnerability
nvd

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

12.6%

BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). Customers using BD Totalys MultiProcessor version 1.70 with Microsoft Windows 10 have additional operating system hardening configurations which increase the attack complexity required to exploit this vulnerability.

Affected configurations

Nvd
Node
bdtotalys_multiprocessor_firmwareRange<1.71
AND
bdtotalys_multiprocessorMatch-
VendorProductVersionCPE
bdtotalys_multiprocessor_firmware*cpe:2.3:o:bd:totalys_multiprocessor_firmware:*:*:*:*:*:*:*:*
bdtotalys_multiprocessor-cpe:2.3:h:bd:totalys_multiprocessor:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "Becton Dickson (BD)",
    "product": "BD Totalys MultiProcessor",
    "versions": [
      {
        "version": "1.70",
        "status": "affected",
        "lessThanOrEqual": "1.70",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2022-40263