CareFusion (BD) · Vulnerability Disclosure

Carefusion Vulnerability Disclosure

Vulnerability disclosure

BD, which acquired CareFusion in 2015 and now ships the CareFusion product lines as BD Alaris and BD Pyxis, runs a published coordinated vulnerability disclosure program through the BD Cybersecurity Trust Center. The disclosure surface is BD-operated and explicitly covers the CareFusion-descended devices: BD publishes product-specific security bulletins and patch pages for BD Alaris and BD Pyxis, which is why this BD-domain program is recorded on the CareFusion record rather than treated as a different company's document. NOTE the absence: there is NO /.well-known/security.txt on any bd.com or carefusion.com host (see well-known/carefusion-well-known.yml), and no bug-bounty program on HackerOne, Bugcrowd or Intigriti was found — disclosure is via a web form, not a bounty platform.

CareFusion (BD) runs a coordinated vulnerability disclosure program on Hackerone.

Automated DispensingBDCareFusionConnected DevicesEMR IntegrationHealthcareHL7Infusion PumpsMedical DevicesPyxisSmart Pumps
Program: Hackerone

Disclosure Policy

Security Contact

Source

Vulnerability Disclosure

carefusion-vulnerability-disclosure.yml Raw ↑
specification: API Commons Vulnerability Disclosure
specificationVersion: '0.1'
provider: CareFusion (BD)
providerId: carefusion
generated: '2026-09-06'
method: searched
source: https://www.bd.com/en-us/about-bd/cybersecurity
description: >-
  BD, which acquired CareFusion in 2015 and now ships the CareFusion product lines as BD
  Alaris and BD Pyxis, runs a published coordinated vulnerability disclosure program through
  the BD Cybersecurity Trust Center. The disclosure surface is BD-operated and explicitly
  covers the CareFusion-descended devices: BD publishes product-specific security bulletins
  and patch pages for BD Alaris and BD Pyxis, which is why this BD-domain program is recorded
  on the CareFusion record rather than treated as a different company's document.
  NOTE the absence: there is NO /.well-known/security.txt on any bd.com or carefusion.com
  host (see well-known/carefusion-well-known.yml), and no bug-bounty program on HackerOne,
  Bugcrowd or Intigriti was found — disclosure is via a web form, not a bounty platform.
program:
  name: BD Coordinated Vulnerability Disclosure
  type: coordinated-disclosure
  bounty: false
  platform: null
  policy_url: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=3
  report_url: https://www.bd.com/en-us/about-bd/cybersecurity
  report_method: >-
    "Report a Cybersecurity Issue" web form for a potential product-related privacy or
    security issue (incident, data breach or vulnerability).
  security_txt: null
  security_txt_note: >-
    No security.txt served. https://www.bd.com/.well-known/security.txt returns HTTP 404
    (HTML error page) to a browser-class fetch.
coordination:
  - name: CVE Program (CVE Numbering Authority)
    detail: BD states it is authorized as a CNA and assigns CVE IDs for its own products.
    evidence: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=4
  - name: Health-ISAC (H-ISAC)
    detail: BD states it shares coordinated vulnerability disclosures through Health-ISAC.
    evidence: https://www.bd.com/en-us/about-bd/cybersecurity
  - name: CISA
    detail: BD links its advisories to CISA cybersecurity advisories.
    evidence: https://www.cisa.gov/news-events/cybersecurity-advisories
advisories:
  - name: BD Alaris product security patches
    url: https://www.bd.com/en-us/about-bd/cybersecurity/patches/security-patches-bd-alaris-products
    status: 200
  - name: BD Pyxis product security patches
    url: https://www.bd.com/en-us/about-bd/cybersecurity/patches/security-patches-bd-pyxis-products
    status: 200
  - name: Bulletins and Patches index
    url: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=2
    status: 200
x-evidence:
  fetched: '2026-09-06'
  probes:
    - url: https://www.bd.com/en-us/about-bd/cybersecurity
      status: 200
    - url: https://www.bd.com/en-us/about-bd/cybersecurity?active-tab=3
      status: 200
    - url: https://www.bd.com/en-us/about-bd/cybersecurity/patches/security-patches-bd-alaris-products
      status: 200
    - url: https://www.bd.com/en-us/about-bd/cybersecurity/patches/security-patches-bd-pyxis-products
      status: 200
    - url: https://www.bd.com/.well-known/security.txt
      status: 404
  note: >-
    The Akamai edge in front of bd.com answers 403 Access Denied to a plain crawler user
    agent; every status above was re-confirmed with a browser-class request the edge serves.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/carefusion-vulnerability-disclosure"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.