Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166
Published: October 26, 2020 / Updated: October 26, 2020
Vulnerability details
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to an improper verification of the cryptographic signature of firmware updates. An attacker with physical access can generate valid firmware updates with arbitrary content that can be used to tamper with devices.
Affected software
Data module compact plus
Battery pack with Wi-Fi
How to mitigate CVE-2020-25166
Battery pack with Wi-Fi - addressed in versions L82, U62
Data module compact plus - update to A12