CVE-2020-25164
CVE-2020-25164 is a medium-severity vulnerability in Bbraun Datamodule Compactplus with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-759.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 5.0
- EPSS exploit prediction: 1% (47th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-759
- Affected product: Bbraun Datamodule Compactplus
- Published:
- Last modified:
Description
A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
Frequently asked questions
- What is CVE-2020-25164?
- A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
- How severe is CVE-2020-25164?
- CVE-2020-25164 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2020-25164 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (47th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-25164?
- CVE-2020-25164 primarily affects Bbraun Datamodule Compactplus. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2020-25164?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-25164 published?
- CVE-2020-25164 was published on 2022-04-14 and last updated on 2026-06-17.
References
- https://www.bbraun.com/en/products-and-therapies/services/b-braun-vulnerability-disclosure-policy/security-advisory.html
- https://www.cisa.gov/uscert/ics/advisories/icsma-20-296-02
Affected products (3)
- cpe:2.3:o:bbraun:datamodule_compactplus:a10:*:*:*:*:*:*:*
- cpe:2.3:o:bbraun:datamodule_compactplus:a11:*:*:*:*:*:*:*
- cpe:2.3:o:bbraun:spacecom:*:*:*:*:*:*:*:*
More vulnerabilities in Bbraun Datamodule Compactplus
- CVE-2020-25166 — High (CVSS 7.6): An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom…
- CVE-2020-25158 — High (CVSS 7.6): A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier,…
- CVE-2020-25150 — High (CVSS 7.6): A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module…
- CVE-2020-25162 — High (CVSS 7.5): A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module…
- CVE-2020-25156 — High (CVSS 7.2): Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10…
- CVE-2020-25160 — Medium (CVSS 6.8): Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module…
All CVEs affecting Bbraun Datamodule Compactplus →
Other CWE-759 vulnerabilities
- CVE-2025-10205 — High (CVSS 8.8): Use of a One-Way Hash with a Predictable Salt vulnerability in ABB FLXEON.This issue affects FLXEON: through…
- CVE-2020-16244 — High (CVSS 7.2): GE Digital APM Classic, Versions 4.4 and prior. Salt is not used for hash calculation of passwords, making it possible…
- CVE-2026-57263 — Medium (CVSS 6.8): A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the…
- CVE-2023-1430 — Medium (CVSS 6.5): The FluentCRM - Marketing Automation For WordPress plugin for WordPress is vulnerable to unauthorized modification of…
- CVE-2025-15631 — Medium (CVSS 5.9): A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing…
- CVE-2025-15544 — Medium (CVSS 5.9): A cryptographic weakness exists in the Omada device adoption process. During adoption, authentication credentials…