Description
The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior to v5.3, Welch Allyn Software Development Kit (SDK): versions prior to v3.2, Welch Allyn Connex Central Station (CS): versions prior to v1.8.6, Welch Allyn Service Monitor: versions prior to v1.7.0.0, Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02, Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02, Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52, Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00).
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14162 | The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior to v5.3, Welch Allyn Software Development Kit (SDK): versions prior to v3.2, Welch Allyn Connex Central Station (CS): versions prior to v1.8.6, Welch Allyn Service Monitor: versions prior to v1.7.0.0, Welch Allyn Connex Vital Signs Monitor (CVSM): versions prior to v2.43.02, Welch Allyn Connex Integrated Wall System (CIWS): versions prior to v2.43.02, Welch Allyn Connex Spot Monitor (CSM): versions prior to v1.52, Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) / Welch Allyn Spot 4400 Vital Signs Extended Care Device: versions prior to v1.11.00). |
References
| Link | Providers |
|---|---|
| https://us-cert.cisa.gov/ics/advisories/icsma-21-152-01 |
|
History
No history.
Subscriptions
Hillrom
Subscribe
Connex Central Station
Subscribe
Connex Device Integration Suite Network Connectivity Engine
Subscribe
Connex Integrated Wall System
Subscribe
Connex Spot Monitor
Subscribe
Connex Vital Signs Monitor
Subscribe
Service Monitor
Subscribe
Service Tool
Subscribe
Software Development Kit
Subscribe
Spot Vital Signs 4400
Subscribe
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-03T20:48:16.852Z
Reserved: 2021-02-19T00:00:00.000Z
Link: CVE-2021-27408
No data.
Status : Modified
Published: 2021-06-11T17:15:10.637
Modified: 2024-11-21T05:57:56.043
Link: CVE-2021-27408
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD