# CVE-2020-25162

## Summary

- **CVE ID:** CVE-2020-25162
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **CWE:** CWE-643
- **Published:** Apr 14, 2022
- **Last Modified:** Mar 14, 2026

## Description

A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.

## Affected Products

- B. Braun Melsungen AG — SpaceCom (unspecified)
- B. Braun Melsungen AG — Battery pack with Wi-Fi (unspecified)
- B. Braun Melsungen AG — Data module compactplus (A10)
- B. Braun Melsungen AG — Data module compactplus (A11)

## References

- [CNA](https://www.cisa.gov/uscert/ics/advisories/icsma-20-296-02)
- [CNA](https://www.bbraun.com/en/products-and-therapies/services/b-braun-vulnerability-disclosure-policy/security-advisory.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.72%
- **EPSS Percentile:** 72.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._