PT-2026-45794 · Spacelabs Healthcare · Sentinel
Vulncheck
·
Published
2026-06-02
·
Updated
2026-06-02
·
CVE-2026-0611
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Spacelabs Healthcare Sentinel versions 10.5.x and higher
Spacelabs Healthcare Sentinel versions prior to 11.6.0
Description
An unauthenticated remote code execution issue exists via a deprecated .NET Remoting HTTP channel exposed on port 8989. This allows attackers to perform arbitrary file read and write operations by providing valid .NET URI endpoints. By writing ASPX webshells to the IIS wwwroot directory, an attacker can achieve remote code execution on the system. This requires that port 8989 has been explicitly made network-accessible through configuration or network policy changes, as it is not exposed by default.
Recommendations
Update Spacelabs Healthcare Sentinel to version 11.6.0 or later.
Restrict network access to port 8989 to prevent unauthorized access to the .NET Remoting channel.
Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sentinel