CVE-2021-33885
moderate-risk
Published 2021-08-25
An Insufficient Verification of Data Authenticity vulnerability in B. Braun SpaceCom2 prior to 012U000062 allows a remote unauthenticated attacker to send the device malicious data that will be used in place of the correct data. This results in full system command access and execution because of the lack of cryptographic signatures on critical data sets.
Do I need to act?
~
6.9% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
10
CVSS 10.0/10
Critical
NETWORK
/ LOW complexity
Affected Products (1)
Spacecom2
Affected Vendors
References (4)
47
/ 100
moderate-risk
Severity
33/34 · Critical
Exploitability
9/34 · Low
Exposure
5/34 · Minimal