CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Philips Holter 2010 Plus, all versions. A vulnerability has been identified that may allow system options that were not purchased to be enabled.
Ovation_ocr400_firmware, Ovation_ocr400, Liebert_challenger_firmware, Liebert_challenger, Rx3i_cpe100_firmware, Rx3i_cpe100, Rx3i_cpe115_firmware, Rx3i_cpe115, Rx3i_cpe302_firmware, Rx3i_cpe302
2020-10-01
N/A
8.8 HIGH
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.
Aestiva_7100_firmware, Aestiva_7100, Aestiva_7900_firmware, Aestiva_7900, Aespire_7100_firmware, Aespire_7100, Aespire_7900_firmware, Aespire_7900, S2020_firmware, S2020
2020-10-02
N/A
5.3 MEDIUM
In GE Aestiva and Aespire versions 7100 and 7900, a vulnerability exists where serial devices are connected via an added unsecured terminal server to a TCP/IP network configuration, which could allow an attacker to remotely modify device configuration and silence alarms.
Ovation_ocr400_firmware, Ovation_ocr400, Liebert_challenger_firmware, Liebert_challenger, Rx3i_cpe100_firmware, Rx3i_cpe100, Rx3i_cpe115_firmware, Rx3i_cpe115, Rx3i_cpe302_firmware, Rx3i_cpe302
2020-08-24
N/A
8.8 HIGH
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long command to the FTP service, which may cause memory corruption that halts the controller or leads to remote code execution and escalation of privileges.
Minimed_508_firmware, Minimed_508, Minimed_paradigm_511_firmware, Minimed_paradigm_511, Minimed_paradigm_512_firmware, Minimed_paradigm_512, Minimed_paradigm_712_firmware, Minimed_paradigm_712, Minimed_paradigm_712e_firmware, Minimed_paradigm_712e
2020-08-24
N/A
8.8 HIGH
In Medtronic MinMed 508 and Medtronic Minimed Paradigm Insulin Pumps, Versions, MiniMed 508 pump – All versions, MiniMed Paradigm 511 pump – All versions, MiniMed Paradigm 512/712 pumps – All versions, MiniMed Paradigm 712E pump–All versions, MiniMed Paradigm 515/715 pumps–All versions, MiniMed Paradigm 522/722 pumps – All versions,MiniMed Paradigm 522K/722K pumps – All versions, MiniMed Paradigm 523/723 pumps – Software versions 2.4A or lower, MiniMed Paradigm 523K/723K pumps – Software, versions 2.4A or lower, MiniMed Paradigm Veo 554/754 pumps – Software versions 2.6A or lower, MiniMed Paradigm Veo 554CM and 754CM models only – Software versions 2.7A or lower, the affected insulin pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access to one of the affected insulin pump models can inject, replay, modify, and/or intercept data. This vulnerability could also allow attackers to change pump settings and control insulin delivery.
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2021-10-28
N/A
4.3 MEDIUM
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from the device, which may allow sensitive information disclosure. Log files must have previously been exported by a legitimate user.
Alaris_gateway_workstation_firmware, Alaris_gateway_workstation, Alaris_gs_syringe_pump_firmware, Alaris_gs_syringe_pump, Alaris_gh_syringe_pump_firmware, Alaris_gh_syringe_pump, Alaris_cc_syringe_pump_firmware, Alaris_cc_syringe_pump, Alaris_tiva_syringe_pump_firmware, Alaris_tiva_syringe_pump
2020-10-02
N/A
5.3 MEDIUM
BD Alaris Gateway versions, 1.0.13,1.1.3 Build 10,1.1.3 MR Build 11,1.1.5, and 1.1.6, The web browser user interface on the Alaris Gateway Workstation does not prevent an attacker with knowledge of the IP address of the Alaris Gateway Workstation terminal to gain access to the status and configuration information of the device.
In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
Zt610_firmware, Zt610, Zt620_firmware, Zt620, Zt510_firmware, Zt510, Zt410_firmware, Zt410, Zt420_firmware, Zt420
2020-10-02
N/A
7.5 HIGH
Zebra Industrial Printers All Versions, Zebra printers are shipped with unrestricted end-user access to front panel options. If the option to use a passcode to limit the functionality of the front panel is applied, specially crafted packets could be sent over the same network to a port on the printer and the printer will respond with an array of information that includes the front panel passcode for the printer. Once the passcode is retrieved, an attacker must have physical access to the front panel of the printer to enter the passcode to access the full functionality of the front panel.
An information disclosure vulnerability exists when the win32k component improperly provides kernel information, aka 'Win32k Information Disclosure Vulnerability'.
