CVE-2022-43557
low-risk
Published 2022-12-05
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
Do I need to act?
-
0.11% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.3/10
Medium
PHYSICAL
/ HIGH complexity
Affected Products (7)
Bodyguard 999-603 Firmware
Bodyguard Duo 999-903 Firmware
Bodyguard Epidural 999-683 Firmware
Bodyguard Pain Manager 999-803 Firmware
Bodyguard T 999-103 Firmware
Bodyguard 323 Colorvision Firmware
Bodyguard 121 Twins Firmware
Affected Vendors
28
/ 100
low-risk
Severity
14/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
14/34 · Moderate