« Volver al listado

CVE-2023-29060

Estado: ModificadaMedia (5.7)—

The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-29060",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-29060",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-06-03T13:56:36.565415Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cybersecurity@bd.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.4,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 0.7
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.7,
          "attackVector": "PHYSICAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.7,
        "exploitabilityScore": 0.9
      }
    ]
  },
  "affected": [
    {
      "source": "cybersecurity@bd.com",
      "affectedData": [
        {
          "vendor": "Becton, Dickinson and Company (BD)",
          "product": "FACSChorus",
          "versions": [
            {
              "status": "affected",
              "version": "5.0",
              "versionType": "custom",
              "lessThanOrEqual": "5.1"
            },
            {
              "status": "affected",
              "version": "3.0",
              "versionType": "custom",
              "lessThanOrEqual": "3.1"
            }
          ],
          "platforms": [
            "Windows",
            "64 bit"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-11-28T20:15:07.230",
  "references": [
    {
      "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "cybersecurity@bd.com"
    },
    {
      "url": "https://www.bd.com/en-us/about-bd/cybersecurity/bulletin/bd-facschorus-software",
      "tags": [
        "Mitigation",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cybersecurity@bd.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-1299"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-306"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The FACSChorus workstation operating system does not restrict what devices can interact with its USB ports. If exploited, a threat actor with physical access to the workstation could gain access to system information and potentially exfiltrate data."
    },
    {
      "lang": "es",
      "value": "El sistema operativo de la estación de trabajo FACSChorus no restringe qué dispositivos pueden interactuar con sus puertos USB. Si se explota, un actor de amenazas con acceso físico a la estación de trabajo podría obtener acceso a la información del sistema y potencialmente filtrar datos."
    }
  ],
  "lastModified": "2026-06-17T05:49:17.217",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bd:facschorus:5.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4D5E0D4F-559B-414E-A627-0BA0937BD7F1"
            },
            {
              "criteria": "cpe:2.3:a:bd:facschorus:5.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "57F63FB2-2AE2-4B5F-8B49-4A0A4549CF3E"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:hp_z2_tower_g9:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "54279DE4-A2A4-4AA6-A05F-931094446F16"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    },
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:bd:facschorus:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2785D17E-800C-4772-A131-5737E9446C01"
            },
            {
              "criteria": "cpe:2.3:a:bd:facschorus:3.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "30FD1DE4-982F-4D14-BB8A-478F8430BC63"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:hp:hp_z2_tower_g5:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "7E9BA28D-9C14-435A-9786-222BE58A9258"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cybersecurity@bd.com"
}