BD is voluntarily sharing this notification with Information Sharing and Analysis Organizations (ISAOs).
BD communicates with our customers about cybersecurity vulnerabilities to enable healthcare providers to manage potential risks through awareness and guidance.
BD is aware of and currently monitoring publicly disclosed vulnerabilities in jQuery v1.7.1 and jQuery-ui v1.10.4 libraries. These third-party vulnerabilities are not specific to BD or our products. BD is providing this update to let customers know which BD products could be affected by these third-party vulnerabilities.
BD has not received any reports of these vulnerability being exploited on BD products.
This notification applies to the following BD products:
BD ACE does not directly affect the function of individual infusion pumps and is not sold in the U.S. This vulnerability does not impact customers who use BD Alaris™ PCU 8015 or BD Alaris™ Systems Manager.
This list does not indicate the patch or device status. The list may be updated if more products are identified. Please check back periodically for updates.
BD is currently planning to update the in-scope BD product that utilizes these third-party components. BD does not have a confirmed schedule at this time. Please refer to the Bulletins and Patches page for all approved product security patching notifications. Please check back periodically for updates.
Additionally, BD recommends the following compensating controls for customers using BD products that utilize the affected software:
For product- or site-specific concerns, contact your BD service representative.