Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qmhj-wg3r-x2h5

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.1

Описание

Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.

Medtronic MyCareLink Smart 25000 all versions are vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.

EPSS

Процентиль: 69%
0.00598
Низкий

8.1 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

Medtronic MyCareLink Smart 25000 is vulnerable to a race condition in the MCL Smart Patient Reader software update system, which allows unsigned firmware to be uploaded and executed on the Patient Reader. If exploited, an attacker could remotely execute code on the MCL Smart Patient Reader device, leading to control of the device.

EPSS

Процентиль: 69%
0.00598
Низкий

8.1 High

CVSS3

Дефекты

CWE-367