Siemens Molecular Imaging Vulnerabilities
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
Threat details
Exploitation of the vulnerabilities affords an attacker remote code execution capabilities on the affected system and the exploits targeting these vulnerabilities are known to be publicly available. An attacker with a low level of skill would be able to exploit these vulnerabilities.
CVE Identifiers:
CVE-2015-1635 - Code Injection - An unauthenticated remote attacker could execute arbitrary code by sending a crafted HTTP request to the Microsoft web server on port 80/TCP and 443/TCP of affected devices.
CVE-2015-1497 - Code Injection - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on port 3465/TCP on affected devices.
CVE-2015-7860 - Buffer Overflow - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on affected devices.
CVE-2015-7861 - Privilege Escalation - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on affected devices.
Remediation steps
CVE Vulnerabilities
Last edited: 17 February 2020 11:39 am