PT-2021-20353 · B. Braun · B. Braun Spacecom2
Published
2021-08-25
·
Updated
2022-07-12
·
CVE-2021-33886
CVSS v3.1
8.8
High
| Vector | AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
B. Braun SpaceCom2 versions prior to 012U000062
Description:
An improper sanitization of input issue in B. Braun SpaceCom2 allows a remote unauthenticated attacker to gain user-level command-line access by passing a raw external string straight through to
printf statements. The attacker is required to be on the same network as the device.Recommendations:
For versions prior to 012U000062, update to version 012U000062 or later to resolve the issue. As a temporary workaround, consider restricting network access to the device to minimize the risk of exploitation.
Exploit
Fix
Use of Externally-Controlled Format String
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
B. Braun Spacecom2