CVE-2020-25166 - CERT CVE
ID CVE-2020-25166
Sažetak An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.
Reference
CVSS
Base: 7.5
Impact: 7.8
Exploitability:8.0
Pristup
VektorSloženostAutentikacija
NETWORK LOW SINGLE
Impact
PovjerljivostCjelovitostDostupnost
NONE COMPLETE PARTIAL
CVSS vektor AV:N/AC:L/Au:S/C:N/I:C/A:P
Zadnje važnije ažuriranje 21-04-2022 - 19:29
Objavljeno 14-04-2022 - 21:15