Lucene search

K
nvd[email protected]NVD:CVE-2021-33885
HistoryAug 25, 2021 - 12:15 p.m.

CVE-2021-33885

2021-08-2512:15:16
CWE-347
web.nvd.nist.gov
6
insufficient verification
b. braun spacecom2
remote access
cryptographic signatures

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.5%

An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.

Affected configurations

Nvd
Node
bbraunspacecom2Range<012u000062
AND
bbrauninfusomat_large_volume_pump_871305uMatch-
OR
bbraunspacestation_8713142uMatch-
VendorProductVersionCPE
bbraunspacecom2*cpe:2.3:o:bbraun:spacecom2:*:*:*:*:*:*:*:*
bbrauninfusomat_large_volume_pump_871305u-cpe:2.3:h:bbraun:infusomat_large_volume_pump_871305u:-:*:*:*:*:*:*:*
bbraunspacestation_8713142u-cpe:2.3:h:bbraun:spacestation_8713142u:-:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.006

Percentile

79.5%

Related for NVD:CVE-2021-33885