← back
CVE-2020-25156highCWE-489

B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
In short

Debug code left active in B. Braun medical devices allows attackers with certain cryptographic keys to gain full control (root access) of the device. This is dangerous because these devices are used in hospitals to manage patient care.

Technical detail

Active debug code in B. Braun SpaceCom (L8/U61) and Data module compactplus (A10, A11) permits unauthenticated root access when cryptographic material is available. Attack vector requires possession of specific cryptographic credentials; impact includes complete device compromise and potential manipulation of medical functionality.

Summary generated and translated by AI from the official description.
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H