Heap-based buffer overflow in Smart Model 25000 Patient Reader - CVE-2020-25187

 

Heap-based buffer overflow in Smart Model 25000 Patient Reader - CVE-2020-25187

Published: December 14, 2020


Vulnerability identifier: #VU48955
CSH Severity: Medium
CVSS v4: 8.5 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25187
CWE-ID: CWE-122
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error. A remote attacker on the local network can run a debug command, trigger heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

Smart Model 25000 Patient Reader

How to mitigate CVE-2020-25187

Install updates from vendor's website.

Smart Model 25000 Patient Reader - update to 5.2

External References

Related Security Bulletins