Vulnerabilities > CVE-2022-3027 - Unspecified vulnerability in Contechealth Cms8000 Firmware

047910
CVSS 5.7 - MEDIUM
Attack vector
ADJACENT_NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
HIGH
Availability impact
NONE
low complexity
contechealth

Summary

The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or display incorrect information.

Vulnerable Configurations

Part Description Count
OS
Contechealth
1
Hardware
Contechealth
1