← Back

CVE-2020-25166

nvd nist
Published: Apr 14, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Exploitability: 2.8 / Impact: 4.2
Source: NVD

Description

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

Affected (3)

2 products
Datamodule Compactplus
Spacecom
Configuration A
2 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Bbraun
Version a10
Version a11
Running on/withPlatform Versions
Bbraun
Datamodule Compactplus
All versions
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to l81
Running on/withPlatform Versions
Bbraun
Spacecom
All versions

References (4)

Source: ics-cert@hq.dhs.gov
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.