Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-52232 | BD Synapsys™, versions 4.20, 4.20 SR1, and 4.30, contain an insufficient session expiration vulnerability. If exploited, threat actors may be able to access, modify or delete sensitive information, including electronic protected health information (ePHI), protected health information (PHI) and personally identifiable information (PII). |
Solution
BD Synapsys™ v4.20 SR2 will be released in June 2022 and will remediate this vulnerability. Customers receiving BD Synapsys™ v4.30 will be allowed to upgrade to v5.10, which is expected to be available by August 2022.
Workaround
Configure the inactivity session timeout in the operating system to match the session expiration timeout in BD Synapsys™. Ensure physical access controls are in place and only authorized end-users have access to BD Synapsys™ workstations. Place a reminder at each computer for users to logout when leaving the BD Synapsys™ workstation. Ensure industry standard network security policies and procedures are followed.
Mon, 16 Sep 2024 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | BD Synapsys™ – Insufficient Session Expiration | BD Synapsys™ – Insufficient Session Expiration |
Status: PUBLISHED
Assigner: BD
Published:
Updated: 2024-09-16T17:43:27.280Z
Reserved: 2022-05-04T00:00:00
Link: CVE-2022-30277
No data.
Status : Modified
Published: 2022-06-02T14:15:51.850
Modified: 2024-11-21T07:02:29.147
Link: CVE-2022-30277
No data.
OpenCVE Enrichment
No data.
EUVD