CVE-2019-10959

UnknownEPSS 2.53%

Last modified

CVE-2019-10959 is a vulnerability of currently unknown severity. BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS, Alaris GH, Alaris CC, Alaris TIVA, The application does not restrict the upload of malicious files during a firmware update.. EPSS estimates a 2.53% chance of exploitation in the next 30 days.

Description

BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS, Alaris GH, Alaris CC, Alaris TIVA, The application does not restrict the upload of malicious files during a firmware update.

Metrics

EPSS Probability
2.53%

82.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
BdAlaris Gateway Workstation Firmware1.1.310
BdAlaris Gateway Workstation Firmware1.215
BdAlaris Gateway Workstation Firmware1.3.014
BdAlaris Gateway Workstation Firmware1.3.113
BdAlaris Gs Syringe Pump Firmware<= 2.3.6
BdAlaris Gh Syringe Pump Firmware<= 2.3.6
BdAlaris Cc Syringe Pump Firmware<= 2.3.6
BdAlaris Tiva Syringe Pump Firmware<= 2.3.6

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-10959?
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and 1.6.1, Additionally, the following products using software Version 2.3.6 and below, Alaris GS, Alaris GH, Alaris CC, Alaris TIVA, The application does not restrict the upload of malicious files during a firmware update.
How severe is CVE-2019-10959?
Severity scoring for CVE-2019-10959 is pending analysis. The EPSS model estimates a 2.53% probability of exploitation in the next 30 days.
How do I fix CVE-2019-10959?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-10959?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST