CVE Vulnerabilities

CVE-2022-47376

Insufficiently Protected Credentials

Published: Jun 13, 2023 | Modified: Jun 24, 2023
CVSS 3.x
7.3
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Alaris_infusion_central Bd 1.1 (including) 1.3.2 (including)

Potential Mitigations

References