Lucene search

K
cvelistIcscertCVELIST:CVE-2022-38069
HistorySep 13, 2022 - 2:54 p.m.

CVE-2022-38069 Contec Health CMS8000

2022-09-1314:54:54
CWE-798
icscert
www.cve.org
3
vulnerability
default credentials
contec health cms8000
privileged access
sensitive patient information
device parameters
threat actor

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

25.2%

Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters

CNA Affected

[
  {
    "product": "CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor",
    "vendor": "Contec Health",
    "versions": [
      {
        "status": "affected",
        "version": "All"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

PHYSICAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

25.2%

Related for CVELIST:CVE-2022-38069