ZOLL Defibrillator Dashboard Vulnerabilities
Six issues are causing vulnerabilities in ZOLL Defibrillator Dashboard management platform.
Summary
Six issues are causing vulnerabilities in ZOLL Defibrillator Dashboard management platform.
Affected platforms
The following platforms are known to be affected:
Zoll Defibrillator Dashboard Versions: all prior to 2.2
Threat details
Introduction
CISA has announced six vulnerabilities in ZOLL Defibrillator Dashboard management platform. If these vulnerabilities were exploited, an attacker could remotely execute arbitrary commands, gain access to sensitive information, implement cross-site scripting, retrieve credentials, escalate privileges, and take control of an affected system.
Vulnerability Details
Six vulnerabilities have been found with the ZOLL Defibrillator Dashboard management platform.
- CVE-2021-27489 - The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
- CVE-2021-27481 - The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.
- CVE-2021-27487 - The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
- CVE-2021-27479 - The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.
- CVE-2021-27485 - The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
- CVE-2021-27483 - The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
Remediation advice
Affected organisations are encouraged to contact their relevant suppliers and upgrade to Defibrillator Dashboard Version 2.2 or later.
Zoll is also recommending that affected organisations should disable the password autocomplete function on browsers accessing the Defibrillator Dashboard and perform frequent local checks to confirm readiness of the devices per the manuals.
CVE Vulnerabilities
Last edited: 18 June 2021 9:47 am