CVE-2020-25162
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.
Affected (3)
Products: Bbraun: Datamodule Compactplus, Spacecom
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version a10 |
| Running on/with | Platform Versions |
|---|---|
Bbraun Datamodule Compactplus | All versions |
References (4)
Source: ics-cert@hq.dhs.gov
Broken Link
Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Broken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.