Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Becton, Dickinson and Company (BD)

First CVE: Feb 13, 2017Active for: 9 yearsTotal CVEs: 33
10.2
VTI Score
Low

Becton, Dickinson and Company is a medical device manufacturer whose vulnerability footprint centers on infusion systems, medication delivery platforms, and hospital information management products such as the Alaris family, Performa, and FacSchorus. The exposure recurs through authentication and access-control weaknesses—including hard-coded credentials, missing authentication for critical functions, and improper protection of alternate hardware interfaces—that are structural concerns in networked medical devices where access control boundaries and credential management demand careful design. A meaningful share of disclosures reach serious severity, reflecting the safety-critical role of these systems in hospital environments. Defenders should prioritize securing network access to these devices, rotating any hard-coded credentials per vendor guidance, and reviewing administrative interfaces for authentication enforcement, particularly across firmware updates and system integrations. Current exploitation activity and severity distribution are shown alongside this summary.

FAUCET AI Generated
33
Total CVEs
More Total CVEs than 98% of tracked vendors
0.1
Avg CVEs / Product / Year
Bottom 1%
6.3
Avg CVSS Score
Higher Avg CVSS Score than 37% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Becton, Dickinson and Company (BD) over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 13, 2017
9 years ago
Most Recent CVE
Nov 28, 2023
969 days ago

Self-Reporting Analysis

Of all the CVEs published by Becton, Dickinson and Company (BD) as a CNA, 95.5% affect products that Becton, Dickinson and Company (BD) develops as a vendor.

95.5%
Self-reported: 21 (95.5%)
Third-party: 1 (4.5%)

Of all the CVEs published that affect products developed by Becton, Dickinson and Company (BD), 63.6% are self-published by Becton, Dickinson and Company (BD) as a CNA.

63.6%
36.4%
Self-published: 21 (63.6%)
Other CNAs: 12 (36.4%)

Products(108 total)

Top CVEs

Signals from CVEs in this vendor scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-10959CRITICAL
BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and
Jun 13, 201910.032NONO
CVE-2018-14786CRITICAL
Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper
Aug 23, 20189.430NONO
CVE-2017-6022CRITICAL
A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior ve
Jun 30, 20179.830NONO
CVE-2019-13517HIGH
In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access pr
Sep 6, 20198.827NONO
CVE-2022-22767HIGH
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are inst
Jun 2, 20228.826NONO
CVE-2022-22765HIGH
BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including ele
Feb 12, 20227.826NONO
CVE-2022-40263HIGH
BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, incl
Nov 4, 20227.825NONO
CVE-2019-10962MEDIUM
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker
Jun 13, 20195.325NONO
CVE-2020-25165HIGH
BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authen
Nov 13, 20207.523NONO
CVE-2019-6517MEDIUM
BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Profe
Feb 6, 20196.823NONO
View all 33 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products33 CVEs
12%
58%
21%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local4 (12.1%)
Network7 (21.2%)
Unknown0 (0.0%)
Physical15 (45.5%)
Adjacent Network7 (21.2%)
Attack Complexity
Low29 (87.9%)
High4 (12.1%)
Unknown0 (0.0%)
User Interaction
None26 (78.8%)
Unknown0 (0.0%)
Required7 (21.2%)
Privileges Required
Low9 (27.3%)
High2 (6.1%)
None22 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Becton, Dickinson and Company (BD).

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Becton, Dickinson and Company (BD) — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Becton, Dickinson and Company (BD)'s Products

View all 2 CNAs →

Top CWEs