VYPR

Multipara Monitor M1000

by Nescomed

CVEs (4)

  • CVE-2020-15482HigAug 26, 2020
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.

  • CVE-2020-15484HigAug 26, 2020
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.

  • CVE-2020-15483MedAug 26, 2020
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.

  • CVE-2020-15485MedAug 26, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.