CVE 9.2 CRITICAL

Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting_CVE-2026-0611

9.2 / 10
CRITICAL
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Description

Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration or network policy changes.

AI Analysis

Unauthenticated remote code execution via .NET Remoting

Basic Information

ID CVE-2026-0611
Source VulnCheck
Published Jun 2, 2026 at 15:39

Affected Product

Vendor Spacelabs Healthcare
Product Sentinel
Version 10.5.0
Affected Versions Spacelabs Healthcare Sentinel 10.5.0

CWE Classification

AI Assessment

AI Score 9.2 / 10
AI Severity Critical
Vendor Spacelabs Healthcare
Product Sentinel
Version 10.5.x, 11.x.x before 11.6.0

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.