Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166

 

Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166

Published: October 26, 2020 / Updated: October 26, 2020


Vulnerability identifier: #VU47915
CSH Severity: Low
CVSS v4: 4.1 [CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25166
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to an improper verification of the cryptographic signature of firmware updates. An attacker with physical access can generate valid firmware updates with arbitrary content that can be used to tamper with devices.


Affected software

SpaceCom
Data module compact plus
Battery pack with Wi-Fi

How to mitigate CVE-2020-25166

Install updates from vendor's website.

SpaceCom - addressed in versions L82, U62
Battery pack with Wi-Fi - addressed in versions L82, U62
Data module compact plus - update to A12

External References

Related Security Bulletins