CVE-2024-5176: Vulnerability in Welch Allyn Configuration Tool Software
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Welch Allyn Configuration Toolto a version that resolves this vulnerability.Fixed in 1.9.4.2 - Configuration
Contact Baxter Technical Support or your Baxter Project Manager to create configuration files as needed for the impacted software to reduce risk.
Welch Allyn Product Configuration Tool / Welch Allyn Configuration Tool create configuration files (as needed) = N/A - Compensating control
Remove the Welch Allyn Configuration Tool from public access (limit access to the tool to authorized users/systems only).
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5176?
CVE-2024-5176 has been classified as a critical vulnerability due to its potential to allow remote services with stolen credentials.
What versions are affected by CVE-2024-5176?
CVE-2024-5176 affects all versions of the Baxter Welch Allyn Configuration Tool up to and including version 1.9.4.1.
How do I fix CVE-2024-5176?
To remediate CVE-2024-5176, upgrade the Baxter Welch Allyn Configuration Tool to a version higher than 1.9.4.1.
What types of attacks can CVE-2024-5176 enable?
CVE-2024-5176 could enable unauthorized remote access and compromise sensitive information by exploiting insufficiently protected credentials.
Is there a workaround for CVE-2024-5176?
There are currently no known workarounds for CVE-2024-5176; it is recommended to apply the necessary updates instead.