CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
38.7%
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
Vendor | Product | Version | CPE |
---|---|---|---|
bbraun | datamodule_compactplus | a10 | cpe:2.3:o:bbraun:datamodule_compactplus:a10:*:*:*:*:*:*:* |
bbraun | datamodule_compactplus | a11 | cpe:2.3:o:bbraun:datamodule_compactplus:a11:*:*:*:*:*:*:* |
bbraun | datamodule_compactplus | - | cpe:2.3:h:bbraun:datamodule_compactplus:-:*:*:*:*:*:*:* |
bbraun | spacecom | * | cpe:2.3:o:bbraun:spacecom:*:*:*:*:*:*:*:* |
bbraun | spacecom | - | cpe:2.3:h:bbraun:spacecom:-:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
SINGLE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:S/C:C/I:C/A:C
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
Percentile
38.7%