BD FACSChorus
BD FACSChorus software (versions 3.0, 3.1, 5.0, 5.1) running on HP Z2 workstations contains multiple weaknesses in authentication, authorization, and access control. These allow a local user with low privileges to modify system configurations, access sensitive information, or escalate privileges. The vulnerabilities stem from hardcoded credentials (CWE-798), missing authentication checks (CWE-306), weak authorization enforcement (CWE-287), and improper access controls (CWE-266, CWE-277). The underlying FACSDiscover S8 and FACSMelody cell sorter instruments are not affected and continue to operate normally.
- Physical access to the BD FACSChorus workstation
- Local user account credentials for the workstation or FACSChorus software
- Low complexity attack requiring only standard user interaction
Patching may require device reboot — plan for process interruption
/api/v1/advisories/c5bd33d0-37e8-40e5-9b41-930dffa56c3fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.