Common vulnerabilities and Exposures (CVE)

Skip to main content

Required CVE Record Information

Description

Contec Health CMS8000 Patient Monitor is vulnerable to an out-of-bounds write, which could allow an attacker to send specially formatted UDP requests in order to write arbitrary data. This could result in remote code execution.

CVSS 2 Total

ScoreSeverityVersionVector String
9.3CRITICAL4.0CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
9.8CRITICAL3.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Product Status

Learn more

Versions 3 Total

Default Status: unaffected

affected

Credits

  • An anonymous researcher reported these vulnerabilities to CISA. finder

Authorized Data Publishers