Lucene search

K
cvelistMitreCVELIST:CVE-2021-33885
HistoryAug 25, 2021 - 11:38 a.m.

CVE-2021-33885

2021-08-2511:38:20
mitre
www.cve.org
4
vulnerability
b. braun spacecom2
remote attacker
data authenticity
cryptographic signatures

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.7

Confidence

High

EPSS

0.006

Percentile

79.5%

An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

AI Score

9.7

Confidence

High

EPSS

0.006

Percentile

79.5%

Related for CVELIST:CVE-2021-33885