CVE-2022-30277
Status: ModifiedMedium (5.7)—
BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII).
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
- Base score: 5.7
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.23%
- Percentile among all scored CVEs: 13
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- CWE-613
- CWE-613
References
Raw JSON (NVD)
Show
{
"id": "CVE-2022-30277",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 3.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 4.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cybersecurity@bd.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 0.5
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.7,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.2,
"exploitabilityScore": 0.5
}
]
},
"affected": [
{
"source": "cybersecurity@bd.com",
"affectedData": [
{
"vendor": "Becton Dickinson (BD)",
"product": "BD Synapsys™",
"versions": [
{
"status": "affected",
"version": "4.20",
"versionType": "custom",
"lessThanOrEqual": "4.30"
}
]
}
]
}
],
"published": "2022-06-02T14:15:51.850",
"references": [
{
"url": "https://cybersecurity.bd.com/bulletins-and-patches/bd-synapsys-insufficient-session-expiration",
"tags": [
"Vendor Advisory"
],
"source": "cybersecurity@bd.com"
},
{
"url": "https://cybersecurity.bd.com/bulletins-and-patches/bd-synapsys-insufficient-session-expiration",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "cybersecurity@bd.com",
"description": [
{
"lang": "en",
"value": "CWE-613"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-613"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII)."
},
{
"lang": "es",
"value": "BD Synapsys™, versiones 4.20, 4.20 SR1, y 4.30, contienen una vulnerabilidad de expiración de sesión insuficiente. Si es explotada, los actores de la amenaza pueden ser capaces de acceder, modificar o eliminar información confidencial, incluyendo información de salud electrónica protegida (ePHI), información de salud protegida (PHI) e información de identificación personal (PII)"
}
],
"lastModified": "2026-06-17T04:43:23.940",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:bd:synapsys:4.20:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "29718815-1C5E-4C2E-AB8E-95CC357DB0AD"
},
{
"criteria": "cpe:2.3:a:bd:synapsys:4.20:sr1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "ECEB919F-91F6-4ABF-8685-5C6385F96572"
},
{
"criteria": "cpe:2.3:a:bd:synapsys:4.30:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B44B121C-256E-4E6D-8462-B37DFA60584C"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cybersecurity@bd.com"
}