<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 21:19:24 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-196756</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-196756</link>
      <description>EUVD-2026-196756</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-196756</guid>
    </item>
    <item>
      <title>fkie_cve-2023-30565</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2023-30565</link>
      <description>&lt;p&gt;An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2023-30565</guid>
    </item>
    <item>
      <title>GHSA-fwqg-xxwv-675c</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fwqg-xxwv-675c</link>
      <description>&lt;p&gt;An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;An insecure connection between Systems Manager and CQI Reporter application could expose infusion data to an attacker.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fwqg-xxwv-675c</guid>
    </item>
    <item>
      <title>gsd-2023-30565</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2023-30565</link>
      <description>gsd-2023-30565</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2023-30565</guid>
    </item>
    <item>
      <title>ICSMA-23-194-01 — BD Alaris System with Guardrails Suite MX</title>
      <link>https://cve.radiocsirt.org/vuln/icsma-23-194-01</link>
      <description>&lt;p&gt;In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the firmware update package for the wireless card is not properly signed and can be modified. In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the configuration from the PCU can be modified without authentication using physical connection to the PCU. In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the data flowing between the PCU and its modules is insecure. A threat actor with physical access could read or modify data by attaching a specially crafted device while an infusion is running. BD Alaris Guardrails Editor (GRE) v12.1.2 and prior has a GRE dataset file within Systems Manager that can be tampered with and distributed to the PCUs. In the BD Alaris Systems Manager (SM) v12.3 and prior, a malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. BD Alaris Systems Manager (SM) v12.3 and prior does not perform input validation during the Device Import Function. An insecure connection between Systems Manager and CQI Reporter v10.17 application could expose infusion data to an attacker. A lack of input validation within Apache Log4Net (due to an outdated software version) could allow a threat actor to execute malicious commands.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the firmware update package for the wireless card is not properly signed and can be modified. In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the configuration from the PCU can be modified without authentication using physical connection to the PCU. In BD Alaris Point-of-Care Unit (PCU) Model 8015 v12.1.3 and prior, the data flowing between the PCU and its modules is insecure. A threat actor with physical access could read or modify data by attaching a specially crafted device while an infusion is running. BD Alaris Guardrails Editor (GRE) v12.1.2 and prior has a GRE dataset file within Systems Manager that can be tampered with and distributed to the PCUs. In the BD Alaris Systems Manager (SM) v12.3 and prior, a malicious file could be uploaded into a System Manager User Import Function resulting in a hijacked session. BD Alaris Systems Manager (SM) v12.3 and prior does not perform input validation during the Device Import Function. An insecure connection between Systems Manager and CQI Reporter v10.17 application could expose infusion data to an attacker. A lack of input validation within Apache Log4Net (due to an outdated software version) could allow a threat actor to execute malicious commands.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/icsma-23-194-01</guid>
    </item>
  </channel>
</rss>
