SB2021121005 - Improper Authentication in Hillrom Welch Allyn Cardio Products



SB2021121005 - Improper Authentication in Hillrom Welch Allyn Cardio Products

Published: December 10, 2021

Security Bulletin ID SB2021121005
Severity
High
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Authentication bypass using an alternate path or channel (CVE-ID: CVE-2021-43935)

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to an improper authentication. A remote attacker can gain access to the application as the supplied AD account, with all associated privileges. 


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.