A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsma-19-241-01 | Third Party Advisory US Government Resource |
https://www.hipaajournal.com/code-execution-vulnerability-identified-in-change-healthcare-cardiology-devices/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Information
Published : 2019-09-06 10:15
Updated : 2020-08-24 10:37
NVD link : CVE-2018-18630
Mitre link : CVE-2018-18630
JSON object : View
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
Products Affected
changehealthcare
- cardiology_firmware
- cardiology
mckesson
- cardiology_firmware
- cardiology
- horizon_cardiology_firmware
- horizon_cardiology