Becton, Dickinson and Company (BD)

First CVE: Feb 11, 2022Active for: 4 years
22
CVEs Published
More CVEs Published than 42% of tracked CNAs
7.3
Avg CVEs / Year
More Avg CVEs / Year than 44% of tracked CNAs
5.9
Avg CVSS Score
Higher Avg CVSS Score than 8% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Becton, Dickinson and Company (BD) as a CNA, 95.5% affect products that Becton, Dickinson and Company (BD) develops as a vendor.

95.5%
Self-reported: 21Third-party: 1

Of all the CVEs published that affect products developed by Becton, Dickinson and Company (BD), 63.6% are self-published by Becton, Dickinson and Company (BD) as a CNA.

63.6%
36.4%
Self-published: 21Published by other CNAs: 12

Trends Over Time

The number and severity of CVEs published by Becton, Dickinson and Company (BD) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 11, 2022
4 years ago
Most Recent CVE
Dec 17, 2024
584 days ago

Top CVEs

All CVEs published by Becton, Dickinson and Company (BD) as a CNA, regardless of affected vendor or product.

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are inst
Jun 2, 20228.826NONO
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including ele
Feb 12, 20227.826NONO
BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, incl
Nov 4, 20227.825NONO
Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive inf
Dec 17, 20248.024NONO
A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session.
Jul 13, 20238.222NONO
The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although s
Jun 13, 20237.322NONO
Alaris Systems Manager does not perform input validation during the Device Import Function.
Jul 13, 20236.921NONO
A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
Jul 13, 20236.721NONO
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensi
Jun 2, 20225.720NONO
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit app
Feb 11, 20225.520NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA22 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local4 (18.2%)
Network1 (4.5%)
Unknown0 (0.0%)
Physical11 (50.0%)
Adjacent Network6 (27.3%)
Attack Complexity
Low21 (95.5%)
High1 (4.5%)
Unknown0 (0.0%)
User Interaction
None17 (77.3%)
Unknown0 (0.0%)
Required5 (22.7%)
Privileges Required
Low9 (40.9%)
High0 (0.0%)
None13 (59.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Becton, Dickinson and Company (BD) as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Becton, Dickinson and Company (BD) as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs