Out-of-bounds read in Hill-Rom Services products - CVE-2021-27408

 

Out-of-bounds read in Hill-Rom Services products - CVE-2021-27408

Published: June 2, 2021


Vulnerability identifier: #VU53731
CSH Severity: Medium
CVSS v4: 5.9 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-27408
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary condition. A remote authenticated attacker on the local network can trigger out-of-bounds read error and read contents of memory on the system.


Affected software

Welch Allyn Service Monitor
Welch Allyn Connex Central Station (CS)
Welch Allyn Service Tool
Welch Allyn Spot Vital Signs 4400 Device (Spot 4400)
Welch Allyn Spot 4400 Vital Signs Extended Care Device
Welch Allyn Connex Spot Monitor (CSM)
Welch Allyn Connex Vital Signs Monitor (CVSM)
Welch Allyn Connex Integrated Wall System (CIWS)
Welch Allyn Software Development Kit (SDK)
Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE)

How to mitigate CVE-2021-27408

Install updates from vendor's website.

Welch Allyn Service Monitor - update to 1.7.0.0
Welch Allyn Connex Central Station (CS) - update to 1.8.6
Welch Allyn Service Tool - update to 1.10
Welch Allyn Spot Vital Signs 4400 Device (Spot 4400) - update to 1.11.00
Welch Allyn Spot 4400 Vital Signs Extended Care Device - update to 1.11.00
Welch Allyn Connex Spot Monitor (CSM) - update to 1.52
Welch Allyn Connex Vital Signs Monitor (CVSM) - update to 2.43.02
Welch Allyn Connex Integrated Wall System (CIWS) - update to 2.43.02
Welch Allyn Software Development Kit (SDK) - update to 3.2
Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE) - update to 5.3

External References

Related Security Bulletins