Cerner's vulnerability footprint, while modestly scoped, centers on healthcare delivery and connectivity products that sit in critical clinical workflows, giving individual flaws outsized operational impact. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across products such as Medico and its Connectivity Engine line, with recurring weaknesses including buffer overflows, SQL injection, and insecure initialization practices that reflect the legacy and real-time demands of healthcare middleware. Defenders should prioritize patching this vendor's advisories given the severity profile and the clinical dependency on these systems; live exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cerner over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-36385CRITICAL A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the d | Aug 24, 2021 | 9.8 | 32 | NO | NO |
CVE-2018-20053CRITICAL An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The hostname, timezone, and NTP server configurations on the CCE device are vulnerable to command injection b | Apr 25, 2019 | 9.8 | 30 | NO | NO |
CVE-2020-11676HIGH Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3). | Apr 29, 2020 | 8.8 | 26 | NO | NO |
CVE-2020-11677HIGH Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3). | Apr 29, 2020 | 8.8 | 25 | NO | NO |
CVE-2018-20052HIGH An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main CCE firmware has NOPASSWD sudo privileges to several utilities that could be used t | Apr 25, 2019 | 7.8 | 24 | NO | NO |
CVE-2020-11675HIGH Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3). | Apr 29, 2020 | 8.8 | 22 | NO | NO |
CVE-2020-11674HIGH Cerner medico 26.00 allows variable reuse, possibly causing data corruption. | Apr 29, 2020 | 8.8 | 22 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cerner.
Media articles that mention a CVE ID that affects a product developed by Cerner — matched by CVE ID, not by vendor name.