Skip to main content

Siemens Molecular Imaging Vulnerabilities

Siemens has identified four vulnerabilities in Siemens Molecular Imagining products running on Windows 7.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

Siemens has identified four vulnerabilities in Siemens Molecular Imagining products running on Windows 7.

Threat details

Exploitation of the vulnerabilities affords an attacker remote code execution capabilities on the affected system and the exploits targeting these vulnerabilities are known to be publicly available. An attacker with a low level of skill would be able to exploit these vulnerabilities.

CVE Identifiers:

CVE-2015-1635 - Code Injection - An unauthenticated remote attacker could execute arbitrary code by sending a crafted HTTP request to the Microsoft web server on port 80/TCP and 443/TCP of affected devices.

CVE-2015-1497 - Code Injection - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on port 3465/TCP on affected devices.

CVE-2015-7860 - Buffer Overflow - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on affected devices.

CVE-2015-7861 - Privilege Escalation - An unauthenticated remote attacker could execute arbitrary code by sending a crafted request to the HP client automation service on affected devices.


Remediation steps

Type Step
  • Where possible, disconnect the product from the network and use in standalone mode - only reconnect once patches are applied.
  • Ensure users have appropriate backups and system restoration procedures.
  • For specific patch and remediation guidance, contact a local Siemens customer service engineer or regional support centre.


Last edited: 17 February 2020 11:39 am