Missing XML Validation in T1 Ventilator - CVE-2020-27282

 

Missing XML Validation in T1 Ventilator - CVE-2020-27282

Published: February 17, 2021


Vulnerability identifier: #VU50739
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27282
CWE-ID: CWE-112
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise the target system.

The vulnerability exists due to an XML validation vulnerability in the ventilator. An authenticated attacker with physical access can upload specially crafted configuration files and render the device persistently unusable. 


Affected software

T1 Ventilator

How to mitigate CVE-2020-27282

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.


External References

Related Security Bulletins