PT-2019-9611 · Mckesson · Mckesson Cardiology

Alfonso Powers

+1

·

Published

2019-09-06

·

Updated

2020-08-24

·

CVE-2018-18630

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McKesson Cardiology versions 13.x through 14.x
Description A vulnerability was found in the McKesson Cardiology product due to insecure file permissions in the default installation. This may allow an attacker with local system access to execute unauthorized arbitrary code.
Recommendations For versions 13.x through 14.x, update the file permissions to secure settings to prevent unauthorized access. As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-18630

Affected Products

Mckesson Cardiology