Lucene search

K
nvd[email protected]NVD:CVE-2020-25152
HistoryApr 14, 2022 - 9:15 p.m.

CVE-2020-25152

2022-04-1421:15:07
CWE-384
web.nvd.nist.gov
3
vulnerability
b. braun melsungen ag
spacecom
session fixation
hijack web sessions
escalate privileges

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS

0.002

Percentile

54.3%

A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.

Affected configurations

Nvd
Node
bbraundatamodule_compactplusMatch-
AND
bbraundatamodule_compactplusMatcha10
OR
bbraundatamodule_compactplusMatcha11
Node
bbraunspacecomMatch-
AND
bbraunspacecomRangel81
VendorProductVersionCPE
bbraundatamodule_compactplus-cpe:2.3:h:bbraun:datamodule_compactplus:-:*:*:*:*:*:*:*
bbraundatamodule_compactplusa10cpe:2.3:o:bbraun:datamodule_compactplus:a10:*:*:*:*:*:*:*
bbraundatamodule_compactplusa11cpe:2.3:o:bbraun:datamodule_compactplus:a11:*:*:*:*:*:*:*
bbraunspacecom-cpe:2.3:h:bbraun:spacecom:-:*:*:*:*:*:*:*
bbraunspacecom*cpe:2.3:o:bbraun:spacecom:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N

EPSS

0.002

Percentile

54.3%

Related for NVD:CVE-2020-25152