BD Diagnostic Solutions products, the BACTEC, COR, EpiCenter, MAX, Phoenix M50 and Synapsys lines, drew ICSMA-24-352-01. CVE-2024-10476, default credentials, base score 8.0. BD published it on its own bulletin page and is remediating through field service.

Default credentials are the logins a device leaves the factory with so it can be set up and serviced, ordinarily documented and ordinarily meant to be replaced once the instrument is in place. That step is skipped often enough that the pattern has become one of the most durable weaknesses in connected equipment. When a whole product line shares one scheme, a credential learned from a single manual or unit generalizes across the family.

An attacker with logical or physical network access uses the shipped login and reads, modifies or deletes data, including PHI. Credit to BD for publishing, because its cybersecurity bulletin page is one of the more complete in the industry, and transparency about your own findings is what regulators and customers increasingly expect. Force credential change on first setup. A device that keeps working with the factory password will still have it in five years, on a network someone eventually reaches.

Instruments of this kind sit at the head of clinical decisions, culturing specimens and returning the results that steer treatment. Access allowing those results to be read, altered or deleted is more than a privacy exposure of the health information they hold; it is a path to delayed or misdirected care when a result is quietly changed or erased. The silence of such tampering is part of the hazard, since a laboratory trusts the figure its analyzer reports.

Repairing a fault embedded in deployed hardware through field service means a technician reaching each installed unit in turn, the slower road taken when a setting cannot be pushed over the network. That the disclosure surfaced on the maker's own security bulletin reflects a wider divide, between makers running a visible product-security process and the many that publish nothing.