An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-17845 An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
Fixes

Solution

B. Braun recommends applying updates: SpaceCom: Version U62 or later (United States), L82 or later (outside the United States) Battery Pack SP with Wi-Fi: Version U62 or later (United States), L82 or later (outside the United States) Data module compactplus: Version A12 or later Please contact your local B. Braun organization to request further help. For more information please see the B. Braun Security Advisory. https://www.bbraun.com/en/products-and-therapies/services/b-braun-vulnerability-disclosure-policy/security-advisory.html


Workaround

As a general security measure, B. Braun recommends protecting the network with appropriate mechanisms: Ensure the devices are not accessible directly from the Internet. Use a firewall and isolate the medical devices from the business network. Please contact your local B. Braun organization to request further help. For more information please see the B. Braun Security Advisory. https://www.bbraun.com/en/products-and-therapies/services/b-braun-vulnerability-disclosure-policy/security-advisory.html

History

Wed, 16 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-04-16T16:29:52.798Z

Reserved: 2020-09-04T00:00:00.000Z

Link: CVE-2020-25154

cve-icon Vulnrichment

Updated: 2024-08-04T15:26:10.179Z

cve-icon NVD

Status : Modified

Published: 2022-04-14T21:15:07.950

Modified: 2024-11-21T05:17:29.330

Link: CVE-2020-25154

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.