CVE-2022-47376

HIGH

Alaris Infusion Central <1.4 - Info Disclosure

Title source: llm

Description

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 11.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

Classification

CWE
CWE-522 CWE-257
Status published

Affected Products (1)

bd/alaris_infusion_central < 1.3.2

Timeline

Published Jun 13, 2023
Tracked Since Feb 18, 2026