CVE Vulnerabilities

CVE-2020-25166

Improper Verification of Cryptographic Signature

Published: Apr 14, 2022 | Modified: Apr 21, 2022
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:S/C:N/I:C/A:P
RedHat/V2
RedHat/V3
Ubuntu

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

Weakness

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Affected Software

Name Vendor Start Version End Version
Datamodule_compactplus Bbraun a10 (including) a10 (including)
Datamodule_compactplus Bbraun a11 (including) a11 (including)

References