← back
CVE-2020-25162highCWE-643

B. Braun SpaceCom, Battery Pack SP with Wi-Fi, and Data module compactplus

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.5epss 1.8%
exploitation probability
1.8%top 24% of all CVEs
observed exploitation
nono source reports it
In short

A vulnerability in B. Braun medical devices allows attackers to inject malicious commands into search queries, bypassing security to access sensitive patient information and gain higher privileges without needing a password.

Technical detail

An XPath injection vulnerability (CWE-643) in SpaceCom L81/U61 and Data module compactplus A10/A11 permits unauthenticated remote attackers to manipulate XPath queries, enabling unauthorized information disclosure and privilege escalation through specially crafted input vectors.

Summary generated and translated by AI from the official description.
A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N