<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T16:06:53.851844+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-230845</id>
    <title>EUVD-2026-230845</title>
    <updated>2026-10-03T16:06:53.928238+00:00</updated>
    <content>EUVD-2026-230845</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-230845"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-38069</id>
    <title>fkie_cve-2022-38069</title>
    <updated>2026-10-03T16:06:53.928278+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-38069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-x446-rh2f-5gh9</id>
    <title>GHSA-x446-rh2f-5gh9</title>
    <updated>2026-10-03T16:06:53.928313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-x446-rh2f-5gh9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-38069</id>
    <title>gsd-2022-38069</title>
    <updated>2026-10-03T16:06:53.928330+00:00</updated>
    <content>gsd-2022-38069</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-38069"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/icsma-22-244-01</id>
    <title>ICSMA-22-244-01 — Contec Health CMS8000 Patient Monitor (Update A)</title>
    <updated>2026-10-03T16:06:53.928342+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A threat actor with momentary access to the device can plug a USB drive in and perform a malicious firmware update, resulting in permanent changes to device functionality. No authentication or controls are in place to prevent a threat actor from maliciously modifying firmware and performing a drive-by attack to load the firmware on any CMS8000 device. The CMS800 device fails while attempting to parse malformed network data sent by a threat actor. A threat actor with network access can remotely issue a specially formatted UDP request that will cause the entire device to crash and require a physical reboot. A UDP broadcast request could be sent that causes a mass denial-of-service attack on all CME8000 devices connected to the same network. Multiple globally default credentials exist across all CMS8000 devices, that once exposed, allow a threat actor with momentary physical access to gain privileged access to any device. Privileged credential access enables the extraction of sensitive patient information or modification of device parameters. Multiple binary application files on the CMS8000 device are compiled with 'not stripped' and 'debug_info' compilation settings. These compiler settings greatly decrease the level of effort for a threat actor to reverse engineer sensitive code and identify additional vulnerabilities. The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name,…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/icsma-22-244-01"/>
  </entry>
</feed>
