SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-27260

Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7…

MEDIUM 5.3EPSS 0.43%

Does this matter?

Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.

Description

Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7 v2.x messages via multiple expected parameters.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
EPSS
0.43% probability · 37th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
innokasmedical/vital signs monitor vc150 firmware
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.