CVE-2021-43935
The impacted products, when configured to use SSO, are affected by an improper authentication vulnerability. This vulnerability allows the application to accept manual entry of any active directory (AD) account provisioned in the application without supplying a password, resulting in access to the application as the supplied AD account, with all associated privileges.
Published:Dec 15, 2021
Last Modified:Nov 21, 2024
EPS:Dec 15, 2021
EPSS Score:0.00197
CVSS Score:8.1
Affected Products
Vendor
Product
Action
Vendor
Baxter
Product
Welch Allyn Connex Cardio
Baxter
Welch Allyn Connex Cardio
Vendor
Baxter
Product
Welch Allyn Diagnostic Cardiology Suite
Baxter
Welch Allyn Diagnostic Cardiology Suite
Vendor
Baxter
Product
Welch Allyn Hscribe Holter Analysis System
Baxter
Welch Allyn Hscribe Holter Analysis System
Vendor
Baxter
Product
Welch Allyn Hscribe Holter Analysis System Firmware
Baxter
Welch Allyn Hscribe Holter Analysis System Firmware
Vendor
Baxter
Product
Welch Allyn Q-stress Cardiac Stress Testing System
Baxter
Welch Allyn Q-stress Cardiac Stress Testing System
Vendor
Baxter
Product
Welch Allyn Q-stress Cardiac Stress Testing System Firmware
Baxter
Welch Allyn Q-stress Cardiac Stress Testing System Firmware
Vendor
Baxter
Product
Welch Allyn Rscribe Resting Ecg System
Baxter
Welch Allyn Rscribe Resting Ecg System
Vendor
Baxter
Product
Welch Allyn Vision Express Holter Analysis System
Baxter
Welch Allyn Vision Express Holter Analysis System
Vendor
Baxter
Product
Welch Allyn Xscribe Cardiac Stress Testing System
Baxter
Welch Allyn Xscribe Cardiac Stress Testing System
Vendor
Baxter
Product
Welch Allyn Xscribe Cardiac Stress Testing System Firmware
Baxter
Welch Allyn Xscribe Cardiac Stress Testing System Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
