A missing protection against path traversal allows to access any file on the server.
The attacked system lacks a mechanism to validate or neutralize directory traversal sequences (e.g., '../') in file paths. An attacker can construct an appropriate network request containing a manipulated path and thus exit the allowed directory. The result is the ability to read arbitrary files accessible to the server process, without requiring authentication.
An attacker can read arbitrary files on the server, including configuration files, credentials, private keys, and other sensitive data. The obtained information can be used for further attacks, including privilege escalation or system takeover.
Apply patches available from the manufacturer according to references published at https://www.bbraun.com/productsecurity
B. Braun products — versions indicated in the manufacturer's references (https://www.bbraun.com/productsecurity)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H