CVE-2022-43557
The BD BodyGuard™ infusion pumps specified allow for access through the RS-232 (serial) port interface. If exploited, threat actors with physical access, specialized equipment and knowledge may be able to configure or disable the pump. No electronic protected health information (ePHI), protected health information (PHI) or personally identifiable information (PII) is stored in the pump.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H
- EPSS probability
- 0.11%
- CWE
- CWE-1299
- Published
- 2022-12-05
- Last modified
- 2026-03-13
Affected products
- Becton, Dickinson and Company (BD) BodyGuard™ Pump
- Becton, Dickinson and Company (BD) BodyGuard™ Pump
- Becton, Dickinson and Company (BD) BodyGuard™ Pump
- Becton, Dickinson and Company (BD) BodyGuard™ Pump
- Becton, Dickinson and Company (BD) BodyGuard™ Pump
Weakness type
Related vulnerabilities
- CVE-2025-35998 — Missing protection mechanism for alternate hardware interface in the Intel(R) Quick Assist...
- CVE-2025-41697 — Shell access to UART Console
- CVE-2025-1073 — Panasonic IR Control Hub (IR Blaster) versions 1.17 and earlier may allow an attacker with physical...
- CVE-2025-26409 — Access to Bootloader and Shell Over Serial Interface
- CVE-2024-47944 — Missing Protection Mechanism for Alternate Hardware Interface
- CVE-2024-39723 — IBM FlashSystem denial of service
- CVE-2023-29063 — Lack of DMA Access Protections
- CVE-2023-29060 — Lack of USB Whitelisting