CVE-2022-26389
HIGHBaxter/Hillrom ELI 380 Resting Electrocardiograph < 2.6.0 - Privilege Escalation
Title source: llmDescription
An improper access control vulnerability may allow privilege escalation.This issue affects: * ELI 380 Resting Electrocardiograph: Versions 2.6.0 and prior; * ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph: Versions 2.3.1 and prior; * ELI 250c/BUR 250c Resting Electrocardiograph: Versions 2.1.2 and prior; * ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph: Versions 2.2.0 and prior.
References (2)
Core 2
Core References
Various Sources
https://hillrom.com/en/responsible-disclosures/
Third Party Advisory, US Government Resource
https://www.cisa.gov/news-events/ics-medical-advisories/icsma-22-167-01
Scores
CVSS v3
7.7
EPSS
0.0027
EPSS Percentile
19.1%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-284
Status
published
Products (4)
Baxter/ Hillrom/ELI 380 Resting Electrocardiograph
< 2.6.0
Welch Allyn/ELI 150c/BUR 150c/MLBUR 150c Resting Electrocardiograph
< 2.2.0
Welch Allyn/ELI 250c/BUR 250c Resting Electrocardiograph
< 2.1.2
Welch Allyn/ELI 280/BUR280/MLBUR 280 Resting Electrocardiograph
< 2.3.1
Published
Feb 07, 2025
Tracked Since
Feb 18, 2026