Multiple binary application files on the CMS8000 device are compiled with not stripped and debug_info compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities.
The product is deployed to unauthorized actors with debugging code still enabled or active, which can create unintended entry points or expose sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Cms8000_firmware | Contechealth | - (including) | - (including) |