Vulnerability Details CVE-2020-25150
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.6%
CVSS Severity
CVSS v3 Score 7.6
CVSS v2 Score 9.0
Products affected by CVE-2020-25150
-
cpe:2.3:h:bbraun:datamodule_compactplus:-
-
cpe:2.3:h:bbraun:spacecom:-
-
cpe:2.3:o:bbraun:datamodule_compactplus:a10
-
cpe:2.3:o:bbraun:datamodule_compactplus:a11
-
cpe:2.3:o:bbraun:spacecom:*