Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-0611— Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting

Quick assessment

Affected
Spacelabs Healthcare Sentinel
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Spacelabs Healthcare Sentinel是美国Spacelabs Healthcare公司的一个心脏病学信息管理系统。 Spacelabs Healthcare Sentinel 10.5.x及更高版本和11.6.0之前的11.x.x版本存在安全漏洞,该漏洞源于通过已弃用的.NET Remoting HTTP通道暴露在端口8989上,可能导致未经身份验证的攻击者通过提供有效的.NET URI端点执行任意文件读写操作,攻击者可向IIS wwwroot目录写入ASPX webshell以实现

CVSS 9.8 · Critical EPSS 0.66% · P49

Affected Version Matrix 1

VendorProduct Version RangeStatus
Spacelabs Healthcare Sentinel 10.5.0< 11.6.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-0611

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Spacelabs Healthcare Sentinel 10.5.x < 11.6.0 Unauthenticated RCE via .NET Remoting
Source: CVE Program / CVE List V5
Vulnerability Description
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI endpoints. Attackers can write ASPX webshells to the IIS wwwroot directory to achieve unauthenticated remote code execution on the system. Port 8989 is not exposed in a default Sentinel installation; exploitation requires that the .NET Remoting port has been explicitly made network-accessible through deliberate configuration or network policy changes.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
关键功能的认证机制缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Spacelabs Healthcare Sentinel 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Spacelabs Healthcare Sentinel是美国Spacelabs Healthcare公司的一个心脏病学信息管理系统。 Spacelabs Healthcare Sentinel 10.5.x及更高版本和11.6.0之前的11.x.x版本存在安全漏洞,该漏洞源于通过已弃用的.NET Remoting HTTP通道暴露在端口8989上,可能导致未经身份验证的攻击者通过提供有效的.NET URI端点执行任意文件读写操作,攻击者可向IIS wwwroot目录写入ASPX webshell以实现
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Spacelabs Healthcare Sentinel 10.5.0 ~ 11.6.0 -

II. Public POCs for CVE-2026-0611

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-0611

登录查看更多情报信息。

Vendor Advisories for CVE-2026-0611 (2)

Vendor Pages for CVE-2026-0611 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-0611

No comments yet


Leave a comment