CVE-2022-47376

HIGH

Alaris Infusion Central <1.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

The Alaris Infusion Central software, versions 1.1 to 1.3.2, may contain a recoverable password after the installation. No patient health data is stored in the database, although some site installations may choose to store personal data.

Scores

CVSS v3 7.3
EPSS 0.0004
EPSS Percentile 12.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-522 CWE-257
Status published
Products (1)
bd/alaris_infusion_central 1.1 - 1.3.2
Published Jun 13, 2023
Tracked Since Feb 18, 2026