CVE-2022-43557

MEDIUMCVSS 5.3/10EPSS 0.22%

Last modified

CVE-2022-43557 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. EPSS estimates a 0.22% chance of exploitation in the next 30 days.

Description

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

EPSS Probability
0.22%

12.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
BdBodyguard 999-603 FirmwareAll versions
BdBodyguard Duo 999-903 FirmwareAll versions
BdBodyguard Epidural 999-683 FirmwareAll versions
BdBodyguard Pain Manager 999-803 FirmwareAll versions
BdBodyguard T 999-103 FirmwareAll versions
BdBodyguard 323 Colorvision FirmwareAll versions
BdBodyguard 121 Twins FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2022-43557?
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
How severe is CVE-2022-43557?
CVE-2022-43557 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.22% probability of exploitation in the next 30 days.
How do I fix CVE-2022-43557?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2022-43557?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST