PT-2019-9611 · Mckesson · Mckesson Cardiology

Alfonso Powers

+1

·

Publicado

2019-09-06

·

Atualizado

2020-08-24

·

CVE-2018-18630

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McKesson Cardiology versions 13.x through 14.x
Description A vulnerability was found in the McKesson Cardiology product due to insecure file permissions in the default installation. This may allow an attacker with local system access to execute unauthorized arbitrary code.
Recommendations For versions 13.x through 14.x, update the file permissions to secure settings to prevent unauthorized access. As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.

Correção

Incorrect Permission

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18630

Produtos afetados

Mckesson Cardiology