MEDIUM🇵🇱 Wersja polska

CVE-2021-33884

CVSS 6.5v3.1pub. 2021-08-25upd. 2024-11-21

An Unrestricted Upload of File with Dangerous Type vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows remote attackers to upload any files to the /tmp directory of the device through the webpage API. This can result in critical files being overwritten.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
  • Bbraun Infusomat Large Volume Pump 871305u

    HW
    Bbraun
    all versions
  • Bbraun Spacecom2

    OS
    Bbraun
    < 012u000062
  • Bbraun Spacestation 8713142u

    HW
    Bbraun
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2021-33885CRITICAL10.0PL ✓same product

B. Braun SpaceCom2 — pominięcie weryfikacji podpisu danych, pełny dostęp do systemu

CVE-2021-33886HIGH8.1same product

An improper sanitization of input vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unau...

CVE-2021-33882MEDIUM6.8same product

A Missing Authentication for Critical Function vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows ...

CVE-2021-33883MEDIUM5.9same product

A Cleartext Transmission of Sensitive Information vulnerability in B. Braun SpaceCom2 prior to 012U000062 allo...

CVE-2020-25172CRITICAL9.8PL ✓same vendor

Path Traversal w B. Braun OnlineSuite — nieautoryzowany upload/download plików