CVE-2020-15482
HIGHNiscomed M1000 Firmware - Unauthenticated Cleartext Transmission of Sensitive Information via Telnet
Title source: llmDescription
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.
References (2)
Core 2
Core References
Product x_refsource_misc
https://www.niscomed.com/multipara-monitor.html
Third Party Advisory x_refsource_misc
https://payatu.com/advisory/unauthenticated-telnet-service-in-niscomed-patient-monitor
Scores
CVSS v3
7.8
EPSS
0.0020
EPSS Percentile
9.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-287
CWE-319
Status
published
Products (1)
niscomed/m1000_multipara_patient_monitor_firmware
Published
Aug 26, 2020
Tracked Since
Feb 18, 2026