漏洞标题
康泰克健康CMS8000患者监护仪存在隐藏功能漏洞
漏洞描述信息
受影响的产品会向一个硬编码的IP地址发送远程访问请求,绕过了现有的设备网络设置。这种情况可能作为后门存在,导致恶意用户能够上传并覆盖设备上的文件。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
使用硬编码的凭证
漏洞标题
Hidden Functionality vulnerability in Contec Health CMS8000 Patient Monitor
漏洞描述信息
The "monitor" binary in the firmware of the affected product attempts to mount to a hard-coded, routable IP address, bypassing existing device network settings to do so. The function also enables the network interface of the device if it is disabled. The function is triggered by attempting to update the device from the user menu. This could serve as a backdoor to the device, and could lead to a malicious actor being able to upload and overwrite files on the device.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
漏洞类别
隐藏功能