Vulnerability Description
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Niscomed | M1000 Multipara Patient Monitor Firmware | - |
| Niscomed | M1000 Multipara Patient Monitor | - |
Related Weaknesses (CWE)
References
- https://payatu.com/advisory/unauthenticated-telnet-service-in-niscomed-patient-mThird Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
- https://payatu.com/advisory/unauthenticated-telnet-service-in-niscomed-patient-mThird Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
FAQ
What is CVE-2020-15482?
CVE-2020-15482 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker t...
How severe is CVE-2020-15482?
CVE-2020-15482 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15482?
Check the references section above for vendor advisories and patch information. Affected products include: Niscomed M1000 Multipara Patient Monitor Firmware, Niscomed M1000 Multipara Patient Monitor.