CVE-2020-27262
Summary
| CVE | CVE-2020-27262 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-01-08 16:15:00 UTC |
| Updated | 2021-01-14 17:18:00 UTC |
| Description | Innokas Yhtymä Oy Vital Signs Monitor VC150 prior to Version 1.7.15 A stored cross-site scripting (XSS) vulnerability exists in the affected products that allow an attacker to inject arbitrary web script or HTML via the filename parameter to multiple update endpoints of the administrative web interface. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Innokasmedical | Vital Signs Monitor Vc150 | - | All | All | All |
| Hardware | Innokasmedical | Vital Signs Monitor Vc150 | - | All | All | All |
| Operating System | Innokasmedical | Vital Signs Monitor Vc150 Firmware | All | All | All | All |
| Operating System | Innokasmedical | Vital Signs Monitor Vc150 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Innokas Yhtymä Oy Vital Signs Monitor | CISA | MISC | us-cert.cisa.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.