PT-2020-15993 · B. Braun · B. Braun Onlinesuite

Birk Kauer

+3

·

Published

2020-11-06

·

Updated

2020-11-13

·

CVE-2020-25170

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions B. Braun OnlineSuite versions prior to AP 3.0
Description An Excel Macro Injection issue exists in the export feature due to mishandled input fields in the Excel export.
Recommendations For versions prior to AP 3.0, consider disabling the export feature to the Excel format until a patch is available. Restrict access to the export functionality to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-25170

Affected Products

B. Braun Onlinesuite