Missing XML Validation in T1 Ventilator - CVE-2020-27282
Published: February 17, 2021
Vulnerability identifier: #VU50739
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:P/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27282
CWE-ID: CWE-112
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise the target system.
The vulnerability exists due to an XML validation vulnerability in the ventilator. An authenticated attacker with physical access can upload specially crafted configuration files and render the device persistently unusable.
Affected software
T1 Ventilator
How to mitigate CVE-2020-27282
Cybersecurity Help is currently unaware of any official solution to address this vulnerability.