PT-2020-14449 · Nescomed · Nescomed Multipara Monitor M1000

Arun Magesh

·

Published

2020-08-26

·

Updated

2021-07-21

·

CVE-2020-15482

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nescomed Multipara Monitor M1000 devices (affected versions not specified)
Description An issue was discovered where the device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.
Recommendations For Nescomed Multipara Monitor M1000 devices, consider disabling the TELNET service or setting a strong password for the admin account to prevent unauthorized access. Restrict access to the device over the local network to minimize the risk of exploitation.

Fix

Improper Authentication

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15482

Affected Products

Nescomed Multipara Monitor M1000