#VU47915 Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166
Published: October 26, 2020 / Updated: October 26, 2020
SpaceCom
Data module compact plus
Battery pack with Wi-Fi
B. Braun Melsungen AG
Description
The vulnerability allows a local attacker to compromise the target system.
The vulnerability exists due to an improper verification of the cryptographic signature of firmware updates. An attacker with physical access can generate valid firmware updates with arbitrary content that can be used to tamper with devices.