Use of hard-coded credentials in B. Braun Melsungen AG products - CVE-2020-25168
Published: October 26, 2020
Vulnerability details
The vulnerability allows a local user to gain full access to vulnerable system.
The vulnerability exists due to presence of hard-coded credentials in application code. A local user can access the affected system using the hard-coded credentials.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Data module compact plus
Battery pack with Wi-Fi
How to mitigate CVE-2020-25168
Battery pack with Wi-Fi - addressed in versions L82, U62
Data module compact plus - update to A12