Medical Devices

Hardware / Firmware Exposure

Authentication & Access Bypass

Unautenticated UART port in niscomed patient monitoring device

Unautenticated UART port in niscomed patient monitoring An issue was discovered on Nescomed Multipara Monitor M1000 devices.The physical UART debug port provides a shell, without requiring a…

6.8
/ 10
Medium
CVSS v3.1
ADVISORY ID
PS41
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-15483
VENDORS
Niscomed
PUBLIC EXPLOIT
PoC public
CWE
CWE-306
PRODUCT
M1000 Multipara Patient Monitor
CVSS VECTOR
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

Unautenticated UART port in niscomed patient monitoring

An issue was discovered on Nescomed Multipara Monitor M1000 devices.The physical UART debug port provides a shell, without requiring a password, with complete root access. This leads to compromised medical data and integrity of the device.

Vulnerability details

Vulnerability details

CVE-2020-15483
CWE-306
Medium | 6.8

Unautenticated UART port in niscomed patient monitoring An issue was discovered on Nescomed Multipara Monitor M1000 devices.The physical UART debug port provides a shell, without requiring a password, with complete root access.

Auth:
None (physical access)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2020-06-22 reported to the vendor

2020-07-22 No response from the vendor and Public disclosure.

Credits

Arun Magesh