Insecure File Permissions in McKesson Cardiology Product 13.x and 14.x: Local System Access Vulnerability

Insecure File Permissions in McKesson Cardiology Product 13.x and 14.x: Local System Access Vulnerability

CVE-2018-18630 · HIGH Severity

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.

Learn more about our Web Application Penetration Testing UK.