Out-of-bounds write in Hill-Rom Services products - CVE-2021-27410

 

Out-of-bounds write in Hill-Rom Services products - CVE-2021-27410

Published: June 2, 2021


Vulnerability identifier: #VU53730
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27410
CWE-ID: CWE-787
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input. A remote authenticated attacker on the local network can trigger out-of-bounds write and execute arbitrary code on the target system.


Affected software

Welch Allyn Service Monitor
Welch Allyn Connex Central Station (CS)
Welch Allyn Service Tool
Welch Allyn Spot Vital Signs 4400 Device (Spot 4400)
Welch Allyn Spot 4400 Vital Signs Extended Care Device
Welch Allyn Connex Spot Monitor (CSM)
Welch Allyn Connex Vital Signs Monitor (CVSM)
Welch Allyn Connex Integrated Wall System (CIWS)
Welch Allyn Software Development Kit (SDK)
Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE)

How to mitigate CVE-2021-27410

Install updates from vendor's website.

Welch Allyn Service Monitor - update to 1.7.0.0
Welch Allyn Connex Central Station (CS) - update to 1.8.6
Welch Allyn Service Tool - update to 1.10
Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) - update to 1.11.00
Welch Allyn Spot 4400 Vital Signs Extended Care Device - update to 1.11.00
Welch Allyn Connex Spot Monitor (CSM) - update to 1.52
Welch Allyn Connex Vital Signs Monitor (CVSM) - update to 2.43.02
Welch Allyn Connex Integrated Wall System (CIWS) - update to 2.43.02
Welch Allyn Software Development Kit (SDK) - update to 3.2
Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE) - update to 5.3

External References

Related Security Bulletins