CVE-2016-9355

MEDIUM

BD Alaris 8015 <9.7 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2016-9355. PoCs published by nadafarafat.

AI-analyzed exploit summary This repository provides a detailed technical analysis of CVE-2016-9355, focusing on unencrypted Wi-Fi credential storage in BD Alaris 8015 firmware. It includes vulnerability root cause, affected components, and compound vulnerabilities.

Description

An issue was discovered in Becton, Dickinson and Company (BD) Alaris 8015 Point of Care (PC) unit, Version 9.5 and prior versions, and Version 9.7. An unauthorized user with physical access to an Alaris 8015 PC unit may be able to obtain unencrypted wireless network authentication credentials and other sensitive technical data by disassembling an Alaris 8015 PC unit and accessing the device's flash memory. Older software versions of the Alaris 8015 PC unit, Version 9.5 and prior versions, store wireless network authentication credentials and other sensitive technical data on the affected device's removable flash memory. Being able to remove the flash memory from the affected device reduces the risk of detection, allowing an attacker to extract stored data at the attacker's convenience.

Exploits (1)

nomisec WRITEUP
by nadafarafat · poc
https://github.com/nadafarafat/bd-alaris-firmware-analysis

This repository provides a detailed technical analysis of CVE-2016-9355, focusing on unencrypted Wi-Fi credential storage in BD Alaris 8015 firmware. It includes vulnerability root cause, affected components, and compound vulnerabilities.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: BD Alaris 8015 PC Unit Firmware v9.33
No auth needed
Prerequisites: Access to firmware image · Tools like binwalk, UBI Reader
devstral-2 · analyzed Jun 10, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/96116
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSMA-17-017-02

Scores

CVSS v3 5.3
EPSS 0.0051
EPSS Percentile 39.3%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Details

CWE
CWE-255
Status published
Products (3)
bd/alaris_8015_pc_unit 9.7
bd/alaris_8015_pc_unit < 9.5
n/a/BD Alaris 8015 Insufficiently Protected Credentials Vulnerabilities BD Alaris 8015 Insufficiently Protected Credentials Vulnerabilities
Published Feb 13, 2017
Tracked Since Feb 18, 2026