CVE-2020-25166

HIGH

B. Braun SpaceCom < L81 and Data module compactplus A10-A11 - Improper Firmware Signature Verification

Title source: llm
STIX 2.1

Description

An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.

References (2)

Core 2

Scores

CVSS v3 7.6
EPSS 0.0044
EPSS Percentile 35.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-347
Status published
Products (3)
bbraun/datamodule_compactplus a10
bbraun/datamodule_compactplus a11
bbraun/spacecom < l81
Published Apr 14, 2022
Tracked Since Feb 18, 2026