PT-2021-11366 · Hamilton Medical Ag · T1-Ventillator

Dr. Oliver Matula

+3

·

Published

2021-03-15

·

Updated

2021-03-22

·

CVE-2020-27282

CVSS v3.1

4.3

Medium

VectorAV:P/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Hamilton Medical AG T1-Ventillator versions 2.2.3 and prior
Description: The issue is related to an XML validation vulnerability in the ventilator, allowing privileged attackers with physical access to render the device persistently unusable by uploading specially crafted configuration files.
Recommendations: For Hamilton Medical AG T1-Ventillator versions 2.2.3 and prior, consider restricting physical access to the device to prevent exploitation of the XML validation vulnerability until a patch is available. As a temporary workaround, consider disabling the upload of configuration files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-27282

Affected Products

T1-Ventillator