PT-2019-9611 · Mckesson · Mckesson Cardiology
Alfonso Powers
+1
·
Published
2019-09-06
·
Updated
2020-08-24
·
CVE-2018-18630
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McKesson Cardiology versions 13.x through 14.x
Description
A vulnerability was found in the McKesson Cardiology product due to insecure file permissions in the default installation. This may allow an attacker with local system access to execute unauthorized arbitrary code.
Recommendations
For versions 13.x through 14.x, update the file permissions to secure settings to prevent unauthorized access. As a temporary workaround, consider restricting local system access to minimize the risk of exploitation.
Fix
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mckesson Cardiology