Loading vulnerability details…
CVSS v3.1
5.3
EPSS
0.43%
Published
Jan 8, 2021
Modified
Nov 21, 2024
Public PoC / Exploit
All weaponized →No public PoC or exploit code indexed for this CVE.
Links to public security research (Exploit-DB, Nuclei, Trickest, GitHub) for defensive use only.
Description
Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 HL7 v2.x injection vulnerabilities exist in the affected products that allow physically proximate attackers with a connected barcode reader to inject HL7 v2.x segments into specific HL7 v2.x messages via multiple expected parameters.
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:NWeaknesses (CWE)
Affected Products (2)
References (2)