#VU47915 Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166

 

#VU47915 Improper Verification of Cryptographic Signature in B. Braun Melsungen AG products - CVE-2020-25166

Published: October 26, 2020 / Updated: October 26, 2020


Vulnerability identifier: #VU47915
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:P/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-25166
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
SpaceCom
Data module compact plus
Battery pack with Wi-Fi
Software vendor:
B. Braun Melsungen AG

Description

The vulnerability allows a local attacker to compromise the target system.

The vulnerability exists due to an improper verification of the cryptographic signature of firmware updates. An attacker with physical access can generate valid firmware updates with arbitrary content that can be used to tamper with devices.


Remediation

Install updates from vendor's website.

External links