Predefined Administrative Account Vulnerability in B. Braun Products
CVE-2025-3321

9.4CRITICAL

Key Information:

Vendor
CVE Published:
6 June 2025

What is CVE-2025-3321?

A critical vulnerability exists in B. Braun medical devices where a predefined administrative account is not only undocumented but also cannot be deactivated. This account is accessible exclusively to local users on the server, which raises potential security concerns. Organizations using these devices should be aware of this vulnerability to ensure appropriate access controls and risk mitigation strategies are implemented.

Affected Version(s)

OnlineSuite 3.0

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Fabian Weber (CODE WHITE GmbH)
Dr. Florian Hauser (CODE WHITE GmbH)
.
CVE-2025-3321 : Predefined Administrative Account Vulnerability in B. Braun Products