Becton, Dickinson and Company (BD)
Self-Reporting Analysis
Of all the CVEs published by Becton, Dickinson and Company (BD) as a CNA, 95.5% affect products that Becton, Dickinson and Company (BD) develops as a vendor.
Of all the CVEs published that affect products developed by Becton, Dickinson and Company (BD), 63.6% are self-published by Becton, Dickinson and Company (BD) as a CNA.
Trends Over Time
The number and severity of CVEs published by Becton, Dickinson and Company (BD) over time
Top CVEs
All CVEs published by Becton, Dickinson and Company (BD) as a CNA, regardless of affected vendor or product.
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22767HIGH Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are inst | Jun 2, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-22765HIGH BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including ele | Feb 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40263HIGH BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, incl | Nov 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2024-10476HIGH Default credentials are used in the above listed BD Diagnostic Solutions products. If exploited, threat actors may be able to access, modify or delete data, including sensitive inf | Dec 17, 2024 | 8.0 | 24 | NO | NO |
CVE-2023-30563HIGH A malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. | Jul 13, 2023 | 8.2 | 22 | NO | NO |
CVE-2022-47376HIGH The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although s | Jun 13, 2023 | 7.3 | 22 | NO | NO |
CVE-2023-30564MEDIUM Alaris Systems Manager does not perform input validation during the Device Import Function. | Jul 13, 2023 | 6.9 | 21 | NO | NO |
CVE-2023-30562MEDIUM A GRE dataset file within Systems Manager can be tampered with and distributed to PCUs.
| Jul 13, 2023 | 6.7 | 21 | NO | NO |
CVE-2022-30277MEDIUM BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensi | Jun 2, 2022 | 5.7 | 20 | NO | NO |
CVE-2022-22766MEDIUM Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit app | Feb 11, 2022 | 5.5 | 20 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (22 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Becton, Dickinson and Company (BD) as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Becton, Dickinson and Company (BD) as a CNA — matched by CVE ID, not by organization name.