BD
BD Facschorus: vulnerabilities and CVEs
BD Facschorus has 7 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs7
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-29066 | Low (3.5) | 0.27% | — | Nov 28, 2023 | The FACSChorus software does not properly assign data access privileges for operating system user accounts. A non-administrative OS account can modify information stored in the local application data folders. |
| CVE-2023-29065 | Medium (4.3) | 0.27% | — | Nov 28, 2023 | The FACSChorus software database can be accessed directly with the privileges of the currently logged-in user. A threat actor with physical access could potentially gain credentials, which could be used to alter or… |
| CVE-2023-29064 | Medium (4.3) | 0.27% | — | Nov 28, 2023 | The FACSChorus software contains sensitive information stored in plaintext. A threat actor could gain hardcoded secrets used by the application, which include tokens and passwords for administrative accounts. |
| CVE-2023-29063 | Low (2.4) | 0.18% | — | Nov 28, 2023 | The FACSChorus workstation does not prevent physical access to its PCI express (PCIe) slots, which could allow a threat actor to insert a PCI card designed for memory capture. A threat actor can then isolate sensitive… |
| CVE-2023-29062 | Low (3.8) | 0.30% | — | Nov 28, 2023 | The Operating System hosting the FACSChorus application is configured to allow transmission of hashed user credentials upon user action without adequately validating the identity of the requested resource. This is… |
| CVE-2023-29061 | Medium (5.2) | 0.38% | — | Nov 28, 2023 | There is no BIOS password on the FACSChorus workstation. A threat actor with physical access to the workstation can potentially exploit this vulnerability to access the BIOS configuration and modify the drive boot order… |
| CVE-2023-29060 | Medium (5.7) | 0.30% | — | Nov 28, 2023 | The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information… |
Other products by BD
Alaris 8015 PCU Firmware · 4Performa · 3Pyxis Medstation ES Firmware · 3Pyxis Anesthesia Station ES Firmware · 3Alaris Systems Manager · 3Pyxis Medbank Firmware · 2Alaris 8015 PC Unit · 2Pyxis Medstation 4000 Firmware · 2Alaris Gateway Workstation Firmware · 2Pyxis Ciisafe Firmware · 2Database Manager · 2Pyxis Logistics Firmware · 2