Vulnerability Description
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Niscomed | M1000 Multipara Patient Monitor Firmware | - |
| Niscomed | M1000 Multipara Patient Monitor | - |
Related Weaknesses (CWE)
References
- https://payatu.com/advisory/lack-of-medical-data-encryption-in-niscomed-patient-Third Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
- https://payatu.com/advisory/lack-of-medical-data-encryption-in-niscomed-patient-Third Party Advisory
- https://www.niscomed.com/multipara-monitor.htmlProduct
FAQ
What is CVE-2020-15484?
CVE-2020-15484 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
How severe is CVE-2020-15484?
CVE-2020-15484 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15484?
Check the references section above for vendor advisories and patch information. Affected products include: Niscomed M1000 Multipara Patient Monitor Firmware, Niscomed M1000 Multipara Patient Monitor.