8.6
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Description
An insecure implementation of the proprietary protocol DNET in Product CGM MEDICO allows attackers within the intranet to eavesdrop and manipulate data on the protocol because encryption is optional for this connection.
Basic Information
ID
CVE-2025-48981
Source
hackerone
Published
Oct 8, 2025 at 00:49
Modified
Oct 8, 2025 at 13:20
Affected Product
Vendor
CompuGroup Medical
Product
CGM MEDICOI
Version
29.0
Affected Versions
CompuGroup Medical CGM MEDICOI 29.0