CVE-2024-5176 is a critical vulnerability in Baxter Welch Allyn Configuration Tool versions 1.9.4.1 and prior, stemming from insufficiently protected credentials. With a CVSS score of 9.4, this flaw allows unauthenticated remote attackers to potentially steal credentials and gain high-impact access to confidential data, integrity, and limited availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high severity warrants immediate attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Baxter | Welch Allyn Configuration Tool | >= 0, <= 1.9.4.1CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.