CVE-2018-20053: Cerner Connectivity Engine 4 Firmware

Critical severity, CVSS 9.8. EPSS: 2.2% chance of exploitation in the next 30 days.

An issue was discovered on Cerner Connectivity Engine (CCE) 4 devices. The hostname, timezone, and NTP server configurations on the CCE device are vulnerable to command injection by sending a crafted configuration file over the network.

Affected products

  • Cerner Connectivity Engine 4 Firmware: before 201812 (fixed in 201812)

Published 2019-04-25. Last modified 2026-06-17.