ZeroHour

CVE-2020-15482

CVSS 3.1
7.8 high
EPSS
<1%p10
Published
()
Modified
Description

An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.

Vendors
niscomed
Products
m1000 multipara patient monitor firmware
Weakness
CWE-287, CWE-319
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.