Description
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration or network policy changes.
Published: 2026-06-02
Score: 9.2 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated remote code execution flaw that allows an attacker to read and write arbitrary files on the system via the deprecated .NET Remoting HTTP channel exposed on port 8989. By supplying valid .NET URI endpoints, an attacker can drop ASPX webshells into the IIS wwwroot directory and achieve full remote code execution. The weakness originates from improper authentication enforcement in the .NET Remoting service, classified as CWE‑306. This flaw can compromise confidentiality, integrity, and availability of the affected Sentinel installation if exploited.

Affected Systems

The affected product is Spacelabs Healthcare Sentinel. Versions 10.5.x and later, as well as 11.x.x prior to 11.6.0, are vulnerable. No specific build or service pack information is given beyond the version ranges. The product is typically deployed in diagnostic cardiology environments and utilizes IIS to host web content.

Risk and Exploitability

The CVSS score of 9.2 reflects a critical security impact with high exploitation potential. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, indicating no publicly confirmed active exploitation yet. However, the flaw requires that the .NET Remoting port is deliberately exposed to the network; by default the port is not open in a standard installation, so an attacker would need to traverse network policies or compromise internal firewall rules. Given the lack of public exploitation evidence, the likelihood remains uncertain, but the severity warrants urgent attention and mitigation.

Generated by OpenCVE AI on June 2, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Sentinel to version 11.6.0 or later to remove the vulnerable .NET Remoting channel.
  • If an upgrade is not immediately possible, disable or remove the .NET Remoting HTTP channel from the Sentinel configuration to eliminate the attack surface.
  • Block incoming traffic to port 8989 on the Sentinel host from untrusted networks using firewalls or network segmentation.

Generated by OpenCVE AI on June 2, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 02 Jun 2026 17:15:00 +0000

Type Values Removed Values Added
Description Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration or network policy changes.
Title Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-06-02T15:39:21.054Z

Reserved: 2026-01-05T16:55:12.556Z

Link: CVE-2026-0611

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-06-02T17:16:25.483

Modified: 2026-06-02T17:19:29.070

Link: CVE-2026-0611

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T18:30:15Z

Weaknesses