Becton, Dickinson and Company is a medical device manufacturer whose vulnerability footprint centers on infusion systems, medication delivery platforms, and hospital information management products such as the Alaris family, Performa, and FacSchorus. The exposure recurs through authentication and access-control weaknesses—including hard-coded credentials, missing authentication for critical functions, and improper protection of alternate hardware interfaces—that are structural concerns in networked medical devices where access control boundaries and credential management demand careful design. A meaningful share of disclosures reach serious severity, reflecting the safety-critical role of these systems in hospital environments. Defenders should prioritize securing network access to these devices, rotating any hard-coded credentials per vendor guidance, and reviewing administrative interfaces for authentication enforcement, particularly across firmware updates and system integrations. Current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Becton, Dickinson and Company (BD) over time
Of all the CVEs published by Becton, Dickinson and Company (BD) as a CNA, 95.5% affect products that Becton, Dickinson and Company (BD) develops as a vendor.
Of all the CVEs published that affect products developed by Becton, Dickinson and Company (BD), 63.6% are self-published by Becton, Dickinson and Company (BD) as a CNA.
Signals from CVEs in this vendor scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10959CRITICAL BD Alaris Gateway Workstation Versions, 1.1.3 Build 10, 1.1.3 MR Build 11, 1.2 Build 15, 1.3.0 Build 14, 1.3.1 Build 13, This does not impact the latest firmware Versions 1.3.2 and | Jun 13, 2019 | 10.0 | 32 | NO | NO |
CVE-2018-14786CRITICAL Becton, Dickinson and Company (BD) Alaris Plus medical syringe pumps (models Alaris GS, Alaris GH, Alaris CC, and Alaris TIVA) versions 2.3.6 and prior are affected by an improper | Aug 23, 2018 | 9.4 | 30 | NO | NO |
CVE-2017-6022CRITICAL A hard-coded password issue was discovered in Becton, Dickinson and Company (BD) PerformA, Version 2.0.14.0 and prior versions, and KLA Journal Service, Version 1.0.51 and prior ve | Jun 30, 2017 | 9.8 | 30 | NO | NO |
CVE-2019-13517HIGH In Pyxis ES Versions 1.3.4 through to 1.6.1 and Pyxis Enterprise Server, with Windows Server Versions 4.4 through 4.12, a vulnerability has been identified where existing access pr | Sep 6, 2019 | 8.8 | 27 | NO | NO |
CVE-2022-22767HIGH Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are inst | Jun 2, 2022 | 8.8 | 26 | NO | NO |
CVE-2022-22765HIGH BD Viper LT system, versions 2.0 and later, contains hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, including ele | Feb 12, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40263HIGH BD Totalys MultiProcessor, versions 1.70 and earlier, contain hardcoded credentials. If exploited, threat actors may be able to access, modify or delete sensitive information, incl | Nov 4, 2022 | 7.8 | 25 | NO | NO |
CVE-2019-10962MEDIUM BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker | Jun 13, 2019 | 5.3 | 25 | NO | NO |
CVE-2020-25165HIGH BD Alaris PC Unit, Model 8015, Versions 9.33.1 and earlier and BD Alaris Systems Manager, Versions 4.33 and earlier The affected products are vulnerable to a network session authen | Nov 13, 2020 | 7.5 | 23 | NO | NO |
CVE-2019-6517MEDIUM BD FACSLyric Research Use Only, Windows 10 Professional Operating System, U.S. and Malaysian Releases, between November 2017 and November 2018 and BD FACSLyric IVD Windows 10 Profe | Feb 6, 2019 | 6.8 | 23 | NO | NO |
Signals from CVEs in this vendor scope (33 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Becton, Dickinson and Company (BD).
Media articles that mention a CVE ID that affects a product developed by Becton, Dickinson and Company (BD) — matched by CVE ID, not by vendor name.