SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-25166

An improper verification of the cryptographic signature of firmware updates of the B.

HIGH 7.1EPSS 0.47%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

CVSS 3.1
7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
EPSS
0.47% probability · 40th percentile
CISA KEV
Not listed
Weakness
CWE-347
Affected
bbraun/datamodule compactplus · bbraun/spacecom
Source
ics-cert@hq.dhs.gov

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.