CVE-2021-43935: ICSMA-21-343-01 Hillrom Welch Allyn Cardio Products
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-43935?
The severity of CVE-2021-43935 is categorized as high due to the potential for unauthorized access through improper authentication.
How do I fix CVE-2021-43935?
To fix CVE-2021-43935, update the affected software to the latest version provided by Baxter that addresses this vulnerability.
Which products are affected by CVE-2021-43935?
CVE-2021-43935 affects several Baxter products, including Welch Allyn Connex Cardio, Diagnostic Cardiology Suite, and Rscribe Resting ECG System among others.
What are the potential impacts of CVE-2021-43935?
The potential impacts of CVE-2021-43935 include unauthorized access to Active Directory accounts without needing a password.
Is authentication compromised in CVE-2021-43935?
Yes, CVE-2021-43935 compromises authentication by allowing manual entry of AD accounts without password verification.