CVE-2019-10962 is a medium-severity vulnerability affecting BD Alaris Gateway Workstation versions 1.0.13 through 1.1.6. It allows an unauthenticated attacker with knowledge of the device's IP address to access status and configuration information via the web browser interface. The CVSS score is 5.3, indicating a network attack vector with low impact on confidentiality and no impact on integrity or availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant media attention and community discussion, with two articles and two community mentions.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0.13CPE matchmatch criteria | cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.0.13:*:*:*:*:*:*:* | ||
1.1.3CPE matchmatch criteria | cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.3:10:*:*:*:*:*:* | ||
1.1.3CPE matchmatch criteria | cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.3:11:*:*:*:*:*:* | ||
1.1.5CPE matchmatch criteria | cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.5:*:*:*:*:*:*:* | ||
1.1.6CPE matchmatch criteria | cpe:2.3:o:bd:alaris_gateway_workstation_firmware:1.1.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.