Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mwfc-gqvv-7hq8

Опубликовано: 15 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.1

Описание

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

EPSS

Процентиль: 25%
0.00088
Низкий

7.1 High

CVSS3

Дефекты

CWE-347

Связанные уязвимости

CVSS3: 7.6
nvd
почти 4 года назад

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

EPSS

Процентиль: 25%
0.00088
Низкий

7.1 High

CVSS3

Дефекты

CWE-347