5.4
CVSSv3

CVE-2022-27494

Published: 21/10/2022 Updated: 21/10/2022
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Aethon TUG Home Base Server versions prior to version 24 are affected by un unauthenticated attacker who can freely access hashed user credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

aethon tug home base server

ICS Advisories

Recent Articles

Critical bug allows attacker to remotely control medical robot
The Register • Jessica Lyons Hardcastle • 01 Jan 1970

Get our weekly newsletter CVSS 9.8 flaws are not what you want in a hospital robot

Mobile robot maker Aethon has fixed a series of vulnerabilities in its Tug hospital robots that, if exploited, could allow a cybercriminal to remotely control thousands of medical machines. Exploiting these five bugs, collectively called JekyllBot:5, required no special privileges or user interaction. And once used, they could allow miscreants to perform all sorts of evil deeds including accessing user credentials and medical records, locking down elevators and doors, surveilling facilities, dis...