Improper Authentication in BD Alaris 8015 PC Unit and BD Alaris Systems Manager - CVE-2020-25165

 

Improper Authentication in BD Alaris 8015 PC Unit and BD Alaris Systems Manager - CVE-2020-25165

Published: November 13, 2020 / Updated: November 18, 2020


Vulnerability identifier: #VU48533
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25165
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can modify the configuration headers of data in transit and perform a denial of service attack, leading to a drop in the wireless capability of the BD Alaris PC Unit, resulting in manual operation of the PC Unit.


Affected software

BD Alaris 8015 PC Unit
BD Alaris Systems Manager

How to mitigate CVE-2020-25165

Install updates from vendor's website.

BD Alaris Systems Manager - addressed in versions 12.0.1, 12.0.2, 12.1.0, 12.1.2

External References

Related Security Bulletins