CVE-2023-0888 is a critical vulnerability affecting the B.Braun Battery Pack SP with WiFi web server (L90/U70 and L92/U92 versions), stemming from improper neutralization of directives in dynamically evaluated code. This flaw allows an authenticated user with specific network and device credentials to gain administrative (root) access to the infusion pump's WiFi communication module. Rated with a CVSS score of 7.2 (HIGH), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 053l000092CPE matchmatch criteria | cpe:2.3:o:bbraun:battery-pack_sp_with_wifi_firmware:*:*:*:*:global:*:*:* | ||
<= 054u000092CPE matchmatch criteria | cpe:2.3:o:bbraun:battery-pack_sp_with_wifi_firmware:*:*:*:*:us:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.