CERT-In Vulnerability Note
CIVN-2022-0287
Multiple vulnerabilities in Hillrom Medical Device Management
Original Issue Date:July 04, 2022
Severity Rating: HIGH
Software Affected
- Hillrom Welch Allyn ELI 380 Resting Electrocardiograph version 2.6.0 and prior
- Hillrom Welch Allyn ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph version 2.3.1 and prior
- Hillrom Welch Allyn ELI 250c/BUR 250c Resting Electrocardiograph version 2.1.2 and prior
- Hillrom Welch Allyn ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph version 2.2.0 and prior
Overview
Multiple vulnerabilities have been reported in Hillrom Medical Devices which could be exploited by an attacker to gain unauthorised access on the targeted system.
Description
1. Use of Hard-coded Password
(
CVE-2022-26388
)
This vulnerability exists in Hillrom Medical Devices due to password being hard-coded for inbound authentication or outbound communication. Successful exploitation of this vulnerability could allow an attacker to gain access to the targeted system.
2. Improper access control
(
CVE-2022-26389
)
This vulnerability exists in Hillrom Medical Devices due to improper implementation of restrictions. Successful exploitation of this vulnerability could allow a threat attacker to gain unauthorized access to resources on the targeted system.
Solution
Apply appropriate upgrade as mentioned
https://www.hillrom.com/en/responsible-disclosures/
Vendor Information
Hillrom
https://www.hillrom.com/en/responsible-disclosures/
References
US-CERT
https://www.cisa.gov/uscert/ics/advisories/icsma-22-167-01
CVE Name
CVE-2022-26388
CVE-2022-26389
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|