ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.1%
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
nono source reports it
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Hillrom · Welch Allyn Connex CardioHillrom · Welch Allyn Diagnostic Cardiology SuiteHillrom · Welch Allyn H-Scribe Holter Analysis SystemHillrom · Welch Allyn Q-Stress Cardiac Stress Testing SystemHillrom · Welch Allyn R-Scribe Resting ECG SystemHillrom · Welch Allyn Vision ExpressHillrom · Welch Allyn X-Scribe Cardiac Stress Testing System