Search

Find a vulnerability

Search criteria

    3 vulnerabilities by hillrom

    CVE-2024-6796 (GCVE-0-2024-6796)

    Vulnerability from cvelistv5 – Published: 2024-09-09 19:28 – Updated: 2024-09-09 20:08
    VLAI
    Title
    Vulnerability in Baxter Connex Health Portal
    Summary
    In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal's database and/or modify content.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 19:51 UTC
    CWE
    • CWE-284 - Improper Access Control
    Impacted products
    Vendor Product Version
    Baxter Connex Health Portal Affected: 0 , < 8/30/2024 (date)
    Create a notification for this product.
    hillrom connex_health_portal Affected: 0 , < 8.30.2024 (custom)
        cpe:2.3:a:hillrom:connex_health_portal:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:hillrom:connex_health_portal:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "connex_health_portal",
                "vendor": "hillrom",
                "versions": [
                  {
                    "lessThan": "8.30.2024",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6796",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T19:51:44.387310Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T20:08:22.237Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Connex Health Portal",
              "vendor": "Baxter",
              "versions": [
                {
                  "lessThan": "8/30/2024",
                  "status": "affected",
                  "version": "0",
                  "versionType": "date"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal\u0027s database and/or modify content.\u0026nbsp;"
                }
              ],
              "value": "In Baxter Connex health portal released before 8/30/2024, an improper access control vulnerability has been found that could allow an unauthenticated attacker to gain unauthorized access to Connex portal\u0027s database and/or modify content."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-115",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-115 Authentication Bypass"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 8.2,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "LOW",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-284",
                  "description": "CWE-284 Improper Access Control",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T19:28:30.647Z",
            "orgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
            "shortName": "Baxter"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Baxter is unaware of any exploitation of this vulnerability in our product and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required.\n\n\u003cbr\u003e"
                }
              ],
              "value": "Baxter is unaware of any exploitation of this vulnerability in our product and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Vulnerability in Baxter Connex Health Portal",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
        "assignerShortName": "Baxter",
        "cveId": "CVE-2024-6796",
        "datePublished": "2024-09-09T19:28:30.647Z",
        "dateReserved": "2024-07-16T17:54:05.755Z",
        "dateUpdated": "2024-09-09T20:08:22.237Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2024-6795 (GCVE-0-2024-6795)

    Vulnerability from cvelistv5 – Published: 2024-09-09 19:24 – Updated: 2024-09-09 20:08
    VLAI
    Title
    Vulnerability in Baxter Connex Health Portal
    Summary
    In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal's database.  An attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content and/or perform administrative operations including shutting down the database.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-09-09 20:04 UTC
    CWE
    • CWE-89 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
    Impacted products
    Vendor Product Version
    Baxter Connex Health Portal Affected: 0 , < 8/30/2024 (date)
    Create a notification for this product.
    hillrom connex_health_portal Affected: 0 , < 8.30.2024 (custom)
        cpe:2.3:a:hillrom:connex_health_portal:*:*:*:*:*:*:*:*
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "affected": [
              {
                "cpes": [
                  "cpe:2.3:a:hillrom:connex_health_portal:*:*:*:*:*:*:*:*"
                ],
                "defaultStatus": "unaffected",
                "product": "connex_health_portal",
                "vendor": "hillrom",
                "versions": [
                  {
                    "lessThan": "8.30.2024",
                    "status": "affected",
                    "version": "0",
                    "versionType": "custom"
                  }
                ]
              }
            ],
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-6795",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-09-09T20:04:42.779977Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-09-09T20:08:01.134Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Connex Health Portal",
              "vendor": "Baxter",
              "versions": [
                {
                  "lessThan": "8/30/2024",
                  "status": "affected",
                  "version": "0",
                  "versionType": "date"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal\u0027s database.\u0026nbsp;\n\nAn attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content \n\nand/or perform administrative operations including shutting down the database."
                }
              ],
              "value": "In Connex health portal released before8/30/2024, SQL injection vulnerabilities were found that could have allowed an unauthenticated attacker to gain unauthorized access to Connex portal\u0027s database.\u00a0\n\nAn attacker could have submitted a crafted payload to Connex portal that could have resulted in modification and disclosure of database content \n\nand/or perform administrative operations including shutting down the database."
            }
          ],
          "impacts": [
            {
              "capecId": "CAPEC-23",
              "descriptions": [
                {
                  "lang": "en",
                  "value": "CAPEC-23 File Content Injection"
                }
              ]
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 10,
                "baseSeverity": "CRITICAL",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "CHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-89",
                  "description": "CWE-89 Improper Neutralization of Special Elements used in an SQL Command (\u0027SQL Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-09-09T19:24:01.776Z",
            "orgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
            "shortName": "Baxter"
          },
          "references": [
            {
              "url": "https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-249-01"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "Baxter is unaware of any exploitation of this vulnerability and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required.\u003cbr\u003e"
                }
              ],
              "value": "Baxter is unaware of any exploitation of this vulnerability and/or the compromise of personal or health data. Baxter patched all impacted systems promptly to address this vulnerability. No user action is required."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "Vulnerability in Baxter Connex Health Portal",
          "x_generator": {
            "engine": "Vulnogram 0.2.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "dba971b9-eb30-4121-91e1-3b45611354aa",
        "assignerShortName": "Baxter",
        "cveId": "CVE-2024-6795",
        "datePublished": "2024-09-09T19:24:01.776Z",
        "dateReserved": "2024-07-16T17:54:02.625Z",
        "dateUpdated": "2024-09-09T20:08:01.134Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2021-43935 (GCVE-0-2021-43935)

    Vulnerability from cvelistv5 – Published: 2021-12-15 18:05 – Updated: 2024-09-16 23:11
    VLAI
    Title
    ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products
    Summary
    The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
    CWE
    • CWE-288 - Authentication Bypass Using an Alternate Path or Channel
    References
    Date Public
    2021-12-09 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-04T04:10:16.298Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://www.cisa.gov/uscert/ics/advisories/icsma-21-343-01"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "Welch Allyn Q-Stress Cardiac Stress Testing System",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.1",
                  "status": "affected",
                  "version": "6.0.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Welch Allyn X-Scribe Cardiac Stress Testing System",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.1",
                  "status": "affected",
                  "version": "5.01",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Welch Allyn Diagnostic Cardiology Suite",
              "vendor": "Hillrom",
              "versions": [
                {
                  "status": "affected",
                  "version": "2.1.0"
                }
              ]
            },
            {
              "product": "Welch Allyn Vision Express",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "6.4.0",
                  "status": "affected",
                  "version": "6.1.0",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Welch Allyn H-Scribe Holter Analysis System",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "6.4.0",
                  "status": "affected",
                  "version": "5.01",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Welch Allyn R-Scribe Resting ECG System",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "7.0.0",
                  "status": "affected",
                  "version": "5.01",
                  "versionType": "custom"
                }
              ]
            },
            {
              "product": "Welch Allyn Connex Cardio",
              "vendor": "Hillrom",
              "versions": [
                {
                  "lessThanOrEqual": "1.1.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "value": "Hillrom reported this vulnerability to CISA"
            }
          ],
          "datePublic": "2021-12-09T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-288",
                  "description": "CWE-288 Authentication Bypass Using an Alternate Path or Channel",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2021-12-15T18:05:16.000Z",
            "orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
            "shortName": "icscert"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://www.cisa.gov/uscert/ics/advisories/icsma-21-343-01"
            }
          ],
          "solutions": [
            {
              "lang": "en",
              "value": "Hillrom recommends users upgrade to the latest product versions when updated products are available. Information on how to update these products to their new versions can be found on the Hillrom disclosure page."
            }
          ],
          "source": {
            "discovery": "UNKNOWN"
          },
          "title": "ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products",
          "workarounds": [
            {
              "lang": "en",
              "value": "-Disable the SSO feature in the respective Modality Manager Configuration settings. Please refer to the instructions for use (IFU) and/or service manual for instructions on how to disable SSO.\n-Apply proper network and physical security controls.\n-Apply authentication for server access."
            }
          ],
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "ics-cert@hq.dhs.gov",
              "DATE_PUBLIC": "2021-12-09T17:10:00.000Z",
              "ID": "CVE-2021-43935",
              "STATE": "PUBLIC",
              "TITLE": "ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "Welch Allyn Q-Stress Cardiac Stress Testing System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "6.0.0",
                                "version_value": "6.3.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn X-Scribe Cardiac Stress Testing System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "5.01",
                                "version_value": "6.3.1"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn Diagnostic Cardiology Suite",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "=",
                                "version_name": "2.1.0",
                                "version_value": "2.1.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn Vision Express",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "6.1.0",
                                "version_value": "6.4.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn H-Scribe Holter Analysis System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "5.01",
                                "version_value": "6.4.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn R-Scribe Resting ECG System",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "5.01",
                                "version_value": "7.0.0"
                              }
                            ]
                          }
                        },
                        {
                          "product_name": "Welch Allyn Connex Cardio",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c=",
                                "version_name": "1.0.0",
                                "version_value": "1.1.1"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "Hillrom"
                  }
                ]
              }
            },
            "credit": [
              {
                "lang": "eng",
                "value": "Hillrom reported this vulnerability to CISA"
              }
            ],
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-288 Authentication Bypass Using an Alternate Path or Channel"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://www.cisa.gov/uscert/ics/advisories/icsma-21-343-01",
                  "refsource": "MISC",
                  "url": "https://www.cisa.gov/uscert/ics/advisories/icsma-21-343-01"
                }
              ]
            },
            "solution": [
              {
                "lang": "en",
                "value": "Hillrom recommends users upgrade to the latest product versions when updated products are available. Information on how to update these products to their new versions can be found on the Hillrom disclosure page."
              }
            ],
            "source": {
              "discovery": "UNKNOWN"
            },
            "work_around": [
              {
                "lang": "en",
                "value": "-Disable the SSO feature in the respective Modality Manager Configuration settings. Please refer to the instructions for use (IFU) and/or service manual for instructions on how to disable SSO.\n-Apply proper network and physical security controls.\n-Apply authentication for server access."
              }
            ]
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6",
        "assignerShortName": "icscert",
        "cveId": "CVE-2021-43935",
        "datePublished": "2021-12-15T18:05:16.799Z",
        "dateReserved": "2021-11-16T00:00:00.000Z",
        "dateUpdated": "2024-09-16T23:11:47.219Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }