CVE-2022-36385: Contec Health CMS8000
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36385?
CVE-2022-36385 is rated as high severity due to the risk of unauthorized firmware modification without authentication.
How do I fix CVE-2022-36385?
To fix CVE-2022-36385, ensure that proper authentication and control mechanisms are implemented for firmware updates.
What devices are affected by CVE-2022-36385?
CVE-2022-36385 affects the contechealth CMS8000 firmware.
What impact does CVE-2022-36385 have on my device?
CVE-2022-36385 can lead to permanent changes in device functionality through unauthorized firmware updates.
Can CVE-2022-36385 be exploited remotely?
CVE-2022-36385 requires physical access to the device to exploit the vulnerability.