An unauthenticated attacker with access to the local network of the
medical office can use known default credentials to gain remote DBA
access to the Elefant Firebird database. The data in the database
includes patient data and login credentials among other sensitive data.
In addition, this enables an attacker to create and overwrite arbitrary
files on the server filesystem with the rights of the Firebird database
("NT AUTHORITY\SYSTEM").
Metrics
Affected Vendors & Products
References
History
Fri, 08 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hasomed
Hasomed elefant |
|
CPEs | cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hasomed
Hasomed elefant |
|
Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 08:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM"). | |
Title | Unprotected Exposed Firebird Database with default credentials | |
Weaknesses | CWE-1393 CWE-419 |
|
References |
|
MITRE
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2024-11-08T08:37:03.702Z
Updated: 2024-11-08T15:24:00.749Z
Reserved: 2024-10-25T07:26:12.628Z
Link: CVE-2024-50588
Vulnrichment
Updated: 2024-11-08T15:23:54.716Z
NVD
Status : Awaiting Analysis
Published: 2024-11-08T09:15:07.680
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-50588
Redhat
No data.