← Back to home
ICSMA-18-277-01  ·  Published 2018-10-04  ·  View on CISA ICS-CERT ↗

Carestream Vue RIS

CVSS 3.7 LOW

Risk Summary

An attacker with access to the network of the affected system can passively read traffic.

CVEs (1)

Remediations

  • Carestream has remediated the vulnerability in the current version of the software and have provided the following workarounds for past versions which are affected. Given the mitigation instructions provided, this vulnerability is considered controlled vs. uncontrolled.
  • Please contact Carestream Support for assistance. Carestream contact information is available at the following location:
  • https://www.carestream.com/en/us/medical/contact-us/world-wide-contacts.
  • Users can open a request through the eService portal at: https://eservice.carestream.com.

Affected Vendors

Carestream

Affected Products (1)

Carestream · RIS Client Builds <=11.2 on Windows 8.1 with IIS 7.5

Affected Sectors

Healthcare and Public Health

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more