​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-42961 ​Softneta MedDream PACS stores usernames and passwords in plaintext. The plaintext storage could be abused by attackers to leak legitimate user’s credentials.
Fixes

Solution

​Softneta recommends users update to v7.2.9.820 https://www.softneta.com/files/meddreampacs/premium/230530/MedDream-PACS-Premium-7.2.9.820.exe  of MedDream PACS Server or patch their current system using Fix-v230712 https://www.softneta.com/files/meddreampacs/premium/Fix-v230712.zip . ​For assistance or additional information about installing the software, please contact Softneta https://www.softneta.com/contacts/  directly.


Workaround

No workaround given by the vendor.

History

Wed, 25 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-09-25T19:58:43.390Z

Reserved: 2023-08-18T16:28:34.432Z

Link: CVE-2023-39227

cve-icon Vulnrichment

Updated: 2024-08-02T18:02:06.660Z

cve-icon NVD

Status : Modified

Published: 2023-09-11T20:15:09.493

Modified: 2024-11-21T08:14:57.243

Link: CVE-2023-39227

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.