CVE-2016-8355

An issue was discovered in Smiths-Medical CADD-Solis Medication Safety Software, Version 1.0; 2.0; 3.0; and 3.1. CADD-Solis Medication Safety Software grants an authenticated user elevated privileges on the SQL database, which would allow an authenticated user to modify drug libraries, add and delete users, and change user permissions. According to Smiths-Medical, physical access to the pump is required to install drug library updates.
References
Link Resource
http://www.securityfocus.com/bid/94630 Third Party Advisory VDB Entry
https://ics-cert.us-cert.gov/advisories/ICSMA-16-306-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:smiths-medical:cadd-solis_medication_safety_software:1.0:*:*:*:*:*:*:*
cpe:2.3:a:smiths-medical:cadd-solis_medication_safety_software:2.0:*:*:*:*:*:*:*
cpe:2.3:a:smiths-medical:cadd-solis_medication_safety_software:3.0:*:*:*:*:*:*:*
cpe:2.3:a:smiths-medical:cadd-solis_medication_safety_software:3.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-13 22:59

Updated : 2024-02-28 15:44


NVD link : CVE-2016-8355

Mitre link : CVE-2016-8355

CVE.ORG link : CVE-2016-8355


JSON object : View

Products Affected

smiths-medical

  • cadd-solis_medication_safety_software
CWE
CWE-306

Missing Authentication for Critical Function