First published: Thu Dec 09 2021(Updated: )
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Baxter Welch Allyn Connex Cardio | >=1.0.0<=1.1.1 | |
Baxter Welch Allyn Diagnostic Cardiology Suite | =2.1.0 | |
Welch Allyn Rscribe Resting ECG System | >=5.01<=7.0.0 | |
Baxter Welch Allyn Vision Express Holter Analysis System | >=6.1.0<=6.4.0 | |
All of | ||
Baxter Welch Allyn Hscribe Holter Analysis System Firmware | >=5.01<=6.4.0 | |
Baxter Welch Allyn Hscribe Holter Analysis System Firmware | ||
All of | ||
Baxter Welch Allyn Q-stress Cardiac Stress Testing System Firmware | >=6.0.0<=6.3.1 | |
Baxter Welch Allyn Q-stress Cardiac Stress Testing System Firmware | ||
All of | ||
Baxter Welch Allyn Xscribe Cardiac Stress Testing System Firmware | >=5.01<=6.3.1 | |
Baxter Welch Allyn Q-stress Cardiac Stress Testing System | ||
Baxter Welch Allyn Hscribe Holter Analysis System Firmware | >=5.01<=6.4.0 | |
Baxter Welch Allyn Hscribe Holter Analysis System Firmware | ||
Baxter Welch Allyn Q-stress Cardiac Stress Testing System Firmware | >=6.0.0<=6.3.1 | |
Baxter Welch Allyn Q-stress Cardiac Stress Testing System Firmware | ||
Baxter Welch Allyn Xscribe Cardiac Stress Testing System Firmware | >=5.01<=6.3.1 | |
Baxter Welch Allyn Q-stress Cardiac Stress Testing System |
Hillrom recommends users upgrade to the latest product versions when updated products are available. Information on how to update these products to their new versions can be found on the Hillrom disclosure page.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-43935 is categorized as high due to the potential for unauthorized access through improper authentication.
To fix CVE-2021-43935, update the affected software to the latest version provided by Baxter that addresses this vulnerability.
CVE-2021-43935 affects several Baxter products, including Welch Allyn Connex Cardio, Diagnostic Cardiology Suite, and Rscribe Resting ECG System among others.
The potential impacts of CVE-2021-43935 include unauthorized access to Active Directory accounts without needing a password.
Yes, CVE-2021-43935 compromises authentication by allowing manual entry of AD accounts without password verification.