Impact
ICU Scandinavia Boomerang has a missing authentication flaw on its device receiver endpoints. An attacker who can reach these endpoints does not need credentials, allowing them to read all facility configuration data and to write arbitrary data into the sensor database. The flaw therefore compromises the confidentiality of configuration details and the integrity of sensor measurements, potentially enabling malicious manipulation of system behavior.
Affected Systems
All installations of ICU Scandinavia Boomerang older than version 2.4.18.029 are affected. Only the fixed release 2.4.18.029 and later protect against this flaw.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate severity, and the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. The vulnerability is not listed in CISA KEV, and it is inferred that exploitation occurs remotely over the network by accessing the vulnerable device receiver endpoints, which do not require authentication.
OpenCVE Enrichment