A vulnerability has been identified in DCA Vantage Analyzer (All versions < V4.5 are affected by CVE-2020-7590. In addition, serial numbers < 40000 running software V4.4.0 are also affected by CVE-2020-15797). Affected devices use a hard-coded password to protect the onboard database. This could allow an attacker to read and or modify the onboard database. Successful exploitation requires direct physical access to the device.
References
| Link | Resource |
|---|---|
| https://www.siemens-healthineers.com/support-documentation/security-advisory | Vendor Advisory |
| https://www.siemens-healthineers.com/support-documentation/security-advisory | Vendor Advisory |
Configurations
Configuration 1 (hide)
| AND |
|
History
21 Nov 2024, 05:37
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.siemens-healthineers.com/support-documentation/security-advisory - Vendor Advisory |
Information
Published : 2020-10-13 16:15
Updated : 2024-11-21 05:37
NVD link : CVE-2020-7590
Mitre link : CVE-2020-7590
CVE.ORG link : CVE-2020-7590
JSON object : View
Products Affected
siemens
- dca_vantage_analyzer
- dca_vantage_analyzer_firmware
CWE
CWE-259
Use of Hard-coded Password
