CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS
Percentile
54.3%
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.
Vendor | Product | Version | CPE |
---|---|---|---|
bbraun | datamodule_compactplus | - | cpe:2.3:h:bbraun:datamodule_compactplus:-:*:*:*:*:*:*:* |
bbraun | datamodule_compactplus | a10 | cpe:2.3:o:bbraun:datamodule_compactplus:a10:*:*:*:*:*:*:* |
bbraun | datamodule_compactplus | a11 | cpe:2.3:o:bbraun:datamodule_compactplus:a11:*:*:*:*:*:*:* |
bbraun | spacecom | - | cpe:2.3:h:bbraun:spacecom:-:*:*:*:*:*:*:* |
bbraun | spacecom | * | cpe:2.3:o:bbraun:spacecom:*:*:*:*:*:*:*:* |
CVSS2
Attack Vector
NETWORK
Attack Complexity
MEDIUM
Authentication
NONE
Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
NONE
AV:N/AC:M/Au:N/C:P/I:P/A:N
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EPSS
Percentile
54.3%