CVE-2024-50589 Vulnerability Details
/
/
/
CVE-2024-50589 Metadata Quick Info
CVE Published: 08/11/2024 |
CVE Updated: 08/11/2024 |
CVE Year: 2024
Source: SEC-VLab |
Vendor: HASOMED |
Product: Elefant
Status : PUBLISHED
CVE-2024-50589 Description
An unauthenticated attacker with access to the local network of the
medical office can query an unprotected Fast Healthcare Interoperability
Resources (FHIR) API to get access to sensitive electronic health
records (EHR).
Metrics
CVSS Version: 3.1 |
Base Score: n/a
Vector: n/a
l➤ Exploitability Metrics:
Attack Vector (AV)*
Attack Complexity (AC)*
Privileges Required (PR)*
User Interaction (UI)*
Scope (S)*
l➤ Impact Metrics:
Confidentiality Impact (C)*
Integrity Impact (I)*
Availability Impact (A)*
Weakness Enumeration (CWE)
CWE-ID: CWE-306
CWE Name: CWE-306 Missing Authentication for Critical Function
Source: HASOMED
Common Attack Pattern Enumeration and Classification (CAPEC)
CAPEC-ID: CAPEC-1
CAPEC Description: CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs
Source: NVD (National Vulnerability Database).