Description
​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.

Published: 2023-09-11
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

​Softneta recommends users update to v7.2.9.820 https://www.softneta.com/files/meddreampacs/premium/230530/MedDream-PACS-Premium-7.2.9.820.exe  of MedDream PACS Server or patch their current system using Fix-v230712 https://www.softneta.com/files/meddreampacs/premium/Fix-v230712.zip . ​For assistance or additional information about installing the software, please contact Softneta https://www.softneta.com/contacts/  directly.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-42961 ​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.
History

Wed, 25 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Softneta Meddream Pacs
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-25T19:58:43.390Z

Reserved: 2023-08-18T16:28:34.432Z

Link: CVE-2023-39227

cve-icon Vulnrichment

Updated: 2024-08-02T18:02:06.660Z

cve-icon NVD

Status : Modified

Published: 2023-09-11T20:15:09.493

Modified: 2024-11-21T08:14:57.243

Link: CVE-2023-39227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses