PT-2019-9611 · Mckesson · Mckesson Cardiology
Alfonso Powers
+1
·
Publicado
2019-09-06
·
Atualizado
2020-08-24
·
CVE-2018-18630
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McKesson Cardiology versions 13.x through 14.x
Description
A vulnerability was found in the McKesson Cardiology product due to insecure file permissions in the default installation. This may allow an attacker with local system access to execute unauthorized arbitrary code.
Recommendations
For versions 13.x through 14.x, update the file permissions to secure settings to prevent unauthorized access. As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.
Correção
Incorrect Permission
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mckesson Cardiology