McKesson's vulnerability profile centers on healthcare information systems, particularly its cardiology and workflow intelligence platforms that support clinical operations. The recurring exposure involves cryptographic and access-control weaknesses such as inadequate encryption strength and incorrect permission assignment, which are critical considerations in systems handling sensitive patient data and clinical workflows. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mckesson over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2001-1546HIGH Pathways Homecare 6.5 uses weak encryption for user names and passwords, which allows local users to gain privileges by recovering the passwords from the pwhc.ini file. | Dec 31, 2001 | 7.8 | 28 | NO | YES |
CVE-2017-16776HIGH Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, which | Dec 15, 2017 | 8.1 | 25 | NO | NO |
CVE-2018-18630HIGH A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to exec | Sep 6, 2019 | 7.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mckesson.
Media articles that mention a CVE ID that affects a product developed by Mckesson — matched by CVE ID, not by vendor name.