7.5
CVSSv3

CVE-2022-38100

Published: 13/09/2022 Updated: 21/07/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

contechealth cms8000 firmware -

ICS Advisories

Contec Health CMS8000
Critical Infrastructure Sectors: Healthcare and Public Health