CVE-2020-16238

MEDIUM

B. Braun SpaceCom < L81 and Data module compactplus A10-A11 - Privilege Escalation via Configuration Import

Title source: llm
STIX 2.1

Description

A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user.

References (2)

Core 2

Scores

CVSS v3 6.7
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (3)
bbraun/datamodule_compactplus a10
bbraun/datamodule_compactplus a11
bbraun/spacecom < l81
Published Apr 14, 2022
Tracked Since Feb 18, 2026