Hillrom manufactures a portfolio of connected clinical monitoring and vital-sign devices, including central stations, spot monitors, and integrated wall systems designed for hospital environments. The observed vulnerability exposure centers on memory-safety weaknesses, specifically out-of-bounds read and write conditions, which reflect the firmware and embedded-system foundations of these networked medical devices. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hillrom over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-27410CRITICAL The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch All | Jun 11, 2021 | 9.8 | 29 | NO | NO |
CVE-2021-27408HIGH The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerabi | Jun 11, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hillrom.
Media articles that mention a CVE ID that affects a product developed by Hillrom — matched by CVE ID, not by vendor name.