mckesson records
3 published records for vendor mckesson.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-326 Inadequate Encryption Strength1
- CWE-732 Incorrect Permission Assignment for Critical Resource1
The weakness classes this vendor ships most often: where to look.
CWEAll records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2017-16776No exploit | Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application bymckesson · conserus workflow intelligence | High8.1 | — | 1.2% | Dec 15, 2017 |
31Monitor | CVE-2001-1546Proof of concept | Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwmckesson · pathways homecare · CWE-326 | High7.8 | — | 0.4% | Dec 31, 2001 |
31Monitor | CVE-2018-18630No exploit | A vulnerability was found in McKesson Cardiology product 13.x and 14.x.mckesson · horizon cardiology firmware · CWE-732 | High7.8 | — | 0.3% | Sep 6, 2019 |
- CVE-2017-1677632Monitor
Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by
HighCVSS 8.1No exploitEPSS 1%mckesson · conserus workflow intelligenceDec 15, 2017
- CVE-2001-154631Monitor
Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passw
HighCVSS 7.8Proof of conceptEPSS 0%mckesson · pathways homecareDec 31, 2001
- CVE-2018-1863031Monitor
A vulnerability was found in McKesson Cardiology product 13.x and 14.x.
HighCVSS 7.8No exploitEPSS 0%mckesson · horizon cardiology firmwareSep 6, 2019