Use of a One-Way Hash without a Salt in B. Braun Melsungen AG products - CVE-2020-25164
Published: October 26, 2020 / Updated: October 26, 2020
Vulnerability details
The vulnerability allows a local attacker to gain access to sensitive information on the system.
The vulnerability exists due to salt is not used for hash calculation of passwords, making it possible to decrypt passwords. A local attacker can recover user credentials of the administrative interface.
Affected software
Data module compact plus
Battery pack with Wi-Fi
How to mitigate CVE-2020-25164
Battery pack with Wi-Fi - addressed in versions L82, U62
Data module compact plus - update to A12