CVE-2022-38069

MEDIUM

ContecHealth CMS8000 Firmware - Use of Hard-coded Credentials

Title source: llm
STIX 2.1

Description

Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://www.cisa.gov/uscert/ics/advisories/icsma-22-244-01

Scores

CVSS v3 4.3
EPSS 0.0028
EPSS Percentile 19.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-798
Status published
Products (1)
contechealth/cms8000_firmware
Published Sep 13, 2022
Tracked Since Feb 18, 2026