CVE-2018-18630
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.
Affected (5)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 12.0 to 12.2 |
| Running on/with | Platform Versions |
|---|---|
Mckesson Horizon Cardiology | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 13.0 |
| Running on/with | Platform Versions |
|---|---|
Mckesson Cardiology | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.1.0 |
| Running on/with | Platform Versions |
|---|---|
Changehealthcare Cardiology | All versions |
References (4)
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource
Timeline
No history available yet.