peter bassill · operator
$ cve CVE-2018-14786 JSON

CVE-2018-14786

9.4
CRITICAL · CVSS 3.0 · EPSS 3.1% (pctl 87)

In your normal cycle

Critical by CVSS (9.4), but no sign of active exploitation.

Description

Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper authentication vulnerability where the software does not perform authentication for functionality that requires a provable user identity, where it may allow a remote attacker to gain unauthorized access to various Alaris Syringe pumps and impact the intended operation of the pump when it is connected to a terminal server via the serial port.

Scoring

CVSS9.4 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
EPSS3.06% — more likely to be exploited than 87% of all CVEs
WeaknessCWE-287
On CISA KEVno
Public exploitnone known
Published2018-08-23
Last modified2026-06-17

Affected (8)

VendorProduct
bdalaris cc
bdalaris cc firmware
bdalaris gh
bdalaris gh firmware
bdalaris gs
bdalaris gs firmware
bdalaris tiva
bdalaris tiva firmware

References

→ the Explorer  ·  watch your stack  ·  NVD