CVE-2024-10476 is a critical vulnerability affecting several BD Diagnostic Solutions products, specifically when BD Synapsys Informatics Solution is installed on a NUC server, due to the use of default credentials. This vulnerability carries a high CVSS score of 8.0, indicating that an authenticated attacker on the adjacent network can easily achieve high impact to confidentiality, integrity, and availability, potentially accessing or manipulating sensitive data like PHI and PII, or causing system shutdowns. While there is no known active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Becton Dickinson & Co | BD BACTEC™ Blood Culture System | >= 0, <= 7.20CNA affecteddefault affected | |
| Becton Dickinson & Co | BD COR™ System | >= 0, <= 8.90CNA affecteddefault affected | |
| Becton Dickinson & Co | BD EpiCenter™ Microbiology Data Management System | >= 0, <= 7.45CNA affecteddefault affected | |
| Becton Dickinson & Co | BD MAX™ System | >= 0, <= 6.10CNA affecteddefault affected | |
| Becton Dickinson & Co | BD Phoenix™ M50 Automated Microbiology System | >= 0, <= 2.70CNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.