Vulnerability Description
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Niscomed | M1000 Multipara Patient Monitor Firmware | - |
| Niscomed | M1000 Multipara Patient Monitor | - |
Related Weaknesses (CWE)
References
- https://payatu.com/advisory/unauthenticated-uart-root-shell--in-niscomed-patientBroken LinkExploitThird Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
- https://payatu.com/advisory/unauthenticated-uart-root-shell--in-niscomed-patientBroken LinkExploitThird Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
FAQ
What is CVE-2020-15483?
CVE-2020-15483 is a vulnerability with a CVSS score of 6.8 (MEDIUM). An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
How severe is CVE-2020-15483?
CVE-2020-15483 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15483?
Check the references section above for vendor advisories and patch information. Affected products include: Niscomed M1000 Multipara Patient Monitor Firmware, Niscomed M1000 Multipara Patient Monitor.