Lucene search

K
cve[email protected]CVE-2020-27282
HistoryMar 15, 2021 - 10:15 p.m.

CVE-2020-27282

2021-03-1522:15:13
CWE-112
web.nvd.nist.gov
42
4
cve-2020-27282
hamilton medical ag
t1-ventilator
xml validation
vulnerability
nvd

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

4.3 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.5%

In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an XML validation vulnerability in the ventilator allows privileged attackers with physical access to render the device persistently unusable by uploading specially crafted configuration files.

Affected configurations

NVD
Node
hamilton-medicalhamilton-t1_firmwareRange2.2.3
AND
hamilton-medicalhamilton-t1Match-

CNA Affected

[
  {
    "product": "Hamilton Medical AG, T1-Ventillator",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Versions 2.2.3 and prior"
      }
    ]
  }
]

Social References

More

2.1 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

4.3 Medium

CVSS3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

4.3 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

27.5%

Related for CVE-2020-27282