Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-30797 | The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges. |
Solution
Hillrom recommends users upgrade to the latest product versions when updated products are available. Information on how to update these products to their new versions can be found on the Hillrom disclosure page.
Workaround
-Disable the SSO feature in the respective Modality Manager Configuration settings. Please refer to the instructions for use (IFU) and/or service manual for instructions on how to disable SSO. -Apply proper network and physical security controls. -Apply authentication for server access.
| Link | Providers |
|---|---|
| https://www.cisa.gov/uscert/ics/advisories/icsma-21-343-01 |
|
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-09-16T23:11:47.219Z
Reserved: 2021-11-16T00:00:00
Link: CVE-2021-43935
No data.
Status : Modified
Published: 2021-12-15T19:15:15.873
Modified: 2024-11-21T06:30:01.987
Link: CVE-2021-43935
No data.
OpenCVE Enrichment
No data.
EUVD