← Back to home
ICSMA-22-151-02  ·  Published 2022-05-31  ·  View on CISA ICS-CERT ↗

BD Synapsys

CVSS 5.7 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to access, modify, or delete sensitive information. This includes electronic protected health information (ePHI), protected health information (PHI), and personally identifiable information (PII).

CVEs (1)

Remediations

  • BD Synapsys v4.20 SR2 will be released in June 2022 and will remediate this vulnerability. Users receiving BD Synapsys v4.30 will be allowed to upgrade to v5.10, which is expected to be available by August 2022.
  • Additionally, BD recommends the following compensating controls for users working with the impacted versions of BD Synapsys:
  • For more information on this issue, please see the associated BD product security bulletin on the BD website.

Affected Vendors

Becton, Dickinson and Company (BD)

Affected Products (1)

Becton, Dickinson and Company (BD) · BD Synapsys 4.20 | 4.20 SR1 | 4.30

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more