CVE Published: 13/09/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: icscert |
Vendor: Contec Health |
Product: CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor Status : PUBLISHED
CVE-2022-38069 Description
Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters
Metrics
CVSS Version: 3.1 |
Base Score: 4.3 MEDIUM Vector: CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L