CVE-2024-5176
Vulnerability in Welch Allyn Configuration Tool Software
Severity Score
9.4
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.
La vulnerabilidad de credenciales insuficientemente protegidas en la herramienta de configuraciĆ³n Baxter Welch Allyn puede permitir servicios remotos con credenciales robadas. Este problema afecta a la herramienta de configuraciĆ³n Welch Allyn: versiones 1.9.4.1 y anteriores.
*Credits:
Baxter reported this vulnerability to CISA.
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-05-21 CVE Reserved
- 2024-05-31 CVE Published
- 2024-06-01 EPSS Updated
- 2024-09-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-522: Insufficiently Protected Credentials
CAPEC
- CAPEC-555: Remote Services with Stolen Credentials
References (1)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Baxter Search vendor "Baxter" | Welch Allyn Configuration Tool Search vendor "Baxter" for product "Welch Allyn Configuration Tool" | <= 1.9.4.1 Search vendor "Baxter" for product "Welch Allyn Configuration Tool" and version " <= 1.9.4.1" | en |
Affected
|