Back to overview

CVE-2021-33885

CRITICAL
10.0
CVSS 3.1
Description
An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.

Metadata

CVE ID
CVE-2021-33885
State
PUBLISHED
Assigner
mitre
Reserved
2021-06-06 00:00 UTC
Published
2021-08-25 11:38 UTC
Last updated
2024-08-04 00:05 UTC
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:N/S:C/UI:N
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AC:L/AV:N/A:N/C:H/I:H/PR:N/S:C/UI:N
Back to overview