PT-2020-14449 · Nescomed · Nescomed Multipara Monitor M1000
Arun Magesh
·
Published
2020-08-26
·
Updated
2021-07-21
·
CVE-2020-15482
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Nescomed Multipara Monitor M1000 devices (affected versions not specified)
Description
An issue was discovered where the device enables an unencrypted TELNET service by default, with a blank password for the
admin account. This allows an attacker to gain root access to the device over the local network.Recommendations
For Nescomed Multipara Monitor M1000 devices, consider disabling the TELNET service or setting a strong password for the
admin account to prevent unauthorized access. Restrict access to the device over the local network to minimize the risk of exploitation.Fix
Improper Authentication
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nescomed Multipara Monitor M1000