Medical Devices

Information Disclosure

Lack of Medical data encryption and integrity in Niscomed Multipara Patient Monitor

Lack of User’s Medical data encryption and integrity An issue was discovered on Nescomed Multipara Monitor M1000 devices.

7.5
/ 10
High
CVSS v3.1
ADVISORY ID
PS39
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-15484
VENDORS
Niscomed
PUBLIC EXPLOIT
None indexed
CWE
CWE-312
PRODUCT
M1000 Multipara Patient Monitor
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Lack of User’s Medical data encryption and integrity

An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering. This data can be accessed using CVE-2020-15482/CVE-2020-15483 and tamper with the user’s medical data.

Vulnerability details

Vulnerability details

CVE-2020-15484
CWE-312
High | 7.5

Lack of User’s Medical data encryption and integrity An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.

Auth:
None (remote)
Impact:
Sensitive data disclosure
DISCLOSURE

Disclosure timeline

2020-06-22 reported to the vendor

2020-07-22 No response from the vendor and Public disclosure.

Credits

Arun Magesh