# CVE-2024-5176

## Summary

- **CVE ID:** CVE-2024-5176
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L)
- **CWE:** CWE-522
- **Published:** May 31, 2024
- **Last Modified:** Mar 13, 2026

## Description

Insufficiently Protected Credentials vulnerability in Baxter Welch Allyn Configuration Tool may allow Remote Services with Stolen Credentials.This issue affects Welch Allyn Configuration Tool: versions 1.9.4.1 and prior.

## Affected Products

- Baxter — Welch Allyn Configuration Tool (0)

## References

- [CNA](https://cisa.gov/news-events/ics-medical-advisories/icsma-24-151-01)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.48%
- **EPSS Percentile:** 39.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._