CVE-2018-18630: Changehealthcare Cardiology Firmware

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

A vulnerability was found in McKesson Cardiology product 13.x and 14.x. Insecure file permissions in the default installation may allow an attacker with local system access to execute unauthorized arbitrary code.

Affected products

  • Changehealthcare Cardiology Firmware: version 14.1.0 only
  • Mckesson Cardiology Firmware: version 13.0 only; version 14.0 only
  • Mckesson Horizon Cardiology Firmware: from 12.0, up to and including 12.2; version 11.0 only

Published 2019-09-06. Last modified 2026-06-17.