Contec Health CMS8000
CVE-2022-38453
3LOW
What is CVE-2022-38453?
Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities.
Affected Version(s)
CMS8000 CONTEC ICU CCU Vital Signs Patient Monitor All
References
CVSS V3.1
Score:
3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Level Nine reported these vulnerabilities to CISA.
