SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-16238

A vulnerability in the configuration import mechanism of the B.

MEDIUM 6.7EPSS 0.25%

Does this matter?

Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.

Description

A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user.

CVSS 3.1
6.7 MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
0.25% probability · 16th percentile
CISA KEV
Not listed
Weakness
CWE-269
Affected
bbraun/datamodule compactplus · bbraun/spacecom
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.