V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-43557
CVE
Medium

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with ph…

CVSS
5.3
Medium
EPSS
0.00
p12
Published
2022-01-01
Updated
2022-01-01
Description

The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.

Tags · CWE
CWE-1299
CAPEC-457
CAPEC-554
Affected products
Bodyguard_121_twins_firmwareBodyguard_323_colorvision_firmwareBodyguard_999-603_firmwareBodyguard_duo_999-903_firmwareBodyguard_epidural_999-683_firmwareBodyguard_pain_manager_999-803_firmwareBodyguard_t_999-103_firmware
CVSS vector
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
Timeline
2022-01-01
Published
2022-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: P
Physical (P)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: L
Low (L)
Integrity Impact
I: L
Low (L)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.002 · p12
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-457 · CWE-1299
└ via CAPEC-457 · CWE-1299
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
bodyguard_121_twins_firmware*Tracked
bodyguard_323_colorvision_firmware*Tracked
bodyguard_999-603_firmware*Tracked
bodyguard_duo_999-903_firmware*Tracked
bodyguard_epidural_999-683_firmware*Tracked
bodyguard_pain_manager_999-803_firmware*Tracked
bodyguard_t_999-103_firmware*Tracked
Source databases
CVE