An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.
History

Wed, 08 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-311
Metrics cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Oct 2025 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Compugroup Medical
Compugroup Medical cgm Medico
Vendors & Products Compugroup Medical
Compugroup Medical cgm Medico

Wed, 08 Oct 2025 01:00:00 +0000

Type Values Removed Values Added
Description An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2025-10-08T13:20:43.202Z

Reserved: 2025-05-29T15:00:04.773Z

Link: CVE-2025-48981

cve-icon Vulnrichment

Updated: 2025-10-08T13:19:10.791Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-08T01:15:32.717

Modified: 2025-10-08T19:38:09.863

Link: CVE-2025-48981

cve-icon Redhat

No data.