CVE-2020-27290

MEDIUM

Hamilton Medical AG T1-Ventillator <2.2.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Hamilton Medical AG,T1-Ventillator versions 2.2.3 and prior, an information disclosure vulnerability in the ventilator allows attackers with physical access to the configuration interface's logs to get valid checksums for tampered configuration files.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsma-21-047-01

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 20.0%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
hamilton-medical/hamilton-t1_firmware < 2.2.3
Published Mar 15, 2021
Tracked Since Feb 18, 2026