Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Cerner

First CVE: Apr 25, 2019Active for: 7 yearsTotal CVEs: 7

Cerner's vulnerability footprint, while modestly scoped, centers on healthcare delivery and connectivity products that sit in critical clinical workflows, giving individual flaws outsized operational impact. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes across products such as Medico and its Connectivity Engine line, with recurring weaknesses including buffer overflows, SQL injection, and insecure initialization practices that reflect the legacy and real-time demands of healthcare middleware. Defenders should prioritize patching this vendor's advisories given the severity profile and the clinical dependency on these systems; live exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
7
Total CVEs
More Total CVEs than 88% of tracked vendors
0.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 9% of tracked vendors
8.9
Avg CVSS Score
Higher Avg CVSS Score than 87% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Cerner over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 25, 2019
7 years ago
Most Recent CVE
Aug 24, 2021
1,796 days ago

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (7 CVEs).

7 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2021-36385CRITICAL
A SQL Injection vulnerability in Cerner Mobile Care 5.0.0 allows remote unauthenticated attackers to execute arbitrary SQL commands via a Fullwidth Apostrophe (aka U+FF07) in the d
Aug 24, 20219.832NONO
CVE-2018-20053CRITICAL
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The hostname, timezone, and NTP server configurations on the CCE device are vulnerable to command injection b
Apr 25, 20199.830NONO
CVE-2020-11676HIGH
Cerner medico 26.00 has a Local Buffer Overflow (issue 2 of 3).
Apr 29, 20208.826NONO
CVE-2020-11677HIGH
Cerner medico 26.00 has a Local Buffer Overflow (issue 3 of 3).
Apr 29, 20208.825NONO
CVE-2018-20052HIGH
An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The user running the main CCE firmware has NOPASSWD sudo privileges to several utilities that could be used t
Apr 25, 20197.824NONO
CVE-2020-11675HIGH
Cerner medico 26.00 has a Local Buffer Overflow (issue 1 of 3).
Apr 29, 20208.822NONO
CVE-2020-11674HIGH
Cerner medico 26.00 allows variable reuse, possibly causing data corruption.
Apr 29, 20208.822NONO
View all 7 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products7 CVEs
71%
29%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local1 (14.3%)
Network2 (28.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (57.1%)
Attack Complexity
Low7 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (7 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Cerner.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Cerner — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Cerner's Products

View all 1 CNAs →

Top CWEs