Description
ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database.
This issue has been fixed in version 2.4.18.029
Published: 2026-07-15
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

ICU Scandinavia Boomerang has a missing authentication flaw on its device receiver endpoints. An attacker who can reach these endpoints does not need credentials, allowing them to read all facility configuration data and to write arbitrary data into the sensor database. The flaw therefore compromises the confidentiality of configuration details and the integrity of sensor measurements, potentially enabling malicious manipulation of system behavior.

Affected Systems

All installations of ICU Scandinavia Boomerang older than version 2.4.18.029 are affected. Only the fixed release 2.4.18.029 and later protect against this flaw.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA KEV, and it is inferred that exploitation occurs remotely over the network by accessing the vulnerable device receiver endpoints, which do not require authentication.

Generated by OpenCVE AI on July 31, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Boomerang to version 2.4.18.029 or later to apply the vendor fix
  • Re‑enable or enforce authentication on all device receiver endpoints to prevent unauthenticated access
  • Audit the sensor database for unauthorized entries and revert or correct any tampered data

Generated by OpenCVE AI on July 31, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Icu Scandinavia
Icu Scandinavia boomerang
Vendors & Products Icu Scandinavia
Icu Scandinavia boomerang

Wed, 15 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote attacker to read full facility configurations and write unauthorized data to the sensor database. This issue has been fixed in version 2.4.18.029
Title Missing Authorization in ICU Scandinavia Boomerang
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Icu Scandinavia Boomerang
cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-07-15T13:02:21.938Z

Reserved: 2026-05-14T14:11:53.521Z

Link: CVE-2026-46459

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses