VendorsZolldefibrillator_dashboardany version
Vulnerabilities

Zoll Defibrillator Dashboard any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-27489
ZOLL Defibrillator Dashboard, v prior to 2.2, The web application allows a non-administrative user to upload a malicious file. This file could allow an attacker to remotely execute arbitrary commands.
Published 2021-06-16 · Modified
8.8EPSS 0.013
CVE-2021-27483
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected products contain insecure filesystem permissions that could allow a lower privilege user to escalate privileges to an administrative level user.
Published 2021-06-16 · Modified
7.8EPSS 0.002
CVE-2021-27485
ZOLL Defibrillator Dashboard, v prior to 2.2,The application allows users to store their passwords in a recoverable format, which could allow an attacker to retrieve the credentials from the web browser.
Published 2021-06-16 · Modified
7.5EPSS 0.012
CVE-2021-27487
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products contain credentials stored in plaintext. This could allow an attacker to gain access to sensitive information.
Published 2021-06-16 · Modified
5.5EPSS 0.002
CVE-2021-27481
ZOLL Defibrillator Dashboard, v prior to 2.2, The affected products utilize an encryption key in the data exchange process, which is hardcoded. This could allow an attacker to gain access to sensitive information.
Published 2021-06-16 · Modified
5.5EPSS 0.002
CVE-2021-27479
ZOLL Defibrillator Dashboard, v prior to 2.2,The affected product’s web application could allow a low privilege user to inject parameters to contain malicious scripts to be executed by higher privilege users.
Published 2021-06-16 · Modified
5.4EPSS 0.005