7.5
CVE-2020-15484
- EPSS 0.13%
- Veröffentlicht 26.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:05:36
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Niscomed ≫ M1000 Multipara Patient Monitor Firmware Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.13% | 0.337 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-312 Cleartext Storage of Sensitive Information
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.