First published: Thu Sep 01 2022(Updated: )
A threat actor with momentary access to the device can plug in a USB drive and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
CMS8000 firmware | ||
contechealth CMS8000 firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36385 is rated as high severity due to the risk of unauthorized firmware modification without authentication.
To fix CVE-2022-36385, ensure that proper authentication and control mechanisms are implemented for firmware updates.
CVE-2022-36385 affects the contechealth CMS8000 firmware.
CVE-2022-36385 can lead to permanent changes in device functionality through unauthorized firmware updates.
CVE-2022-36385 requires physical access to the device to exploit the vulnerability.