Niscomed's vulnerability footprint centers on its M1000 Multiparameter Patient Monitor and associated firmware, medical-device products where the recurring issues cluster around sensitive-data handling and authentication controls. The durable signal reflects the clinical-system context: cleartext storage and transmission of patient information, improper authentication mechanisms, and missing protections on critical functions that should be guarded in healthcare environments. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Niscomed over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-15482HIGH An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This | Aug 26, 2020 | 7.8 | 23 | NO | NO |
CVE-2020-15483MEDIUM An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access. | Aug 26, 2020 | 6.8 | 21 | NO | NO |
CVE-2020-15485MEDIUM An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering. | Aug 26, 2020 | 5.5 | 19 | NO | NO |
CVE-2020-15484HIGH An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection agai | Aug 26, 2020 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Niscomed.
Media articles that mention a CVE ID that affects a product developed by Niscomed — matched by CVE ID, not by vendor name.