An unauthenticated attacker with access to the local network of the
medical office can use known default credentials to gain remote DBA
access to the Elefant Firebird database. The data in the database
includes patient data and login credentials among other sensitive data.
In addition, this enables an attacker to create and overwrite arbitrary
files on the server filesystem with the rights of the Firebird database
("NT AUTHORITY\SYSTEM").
Advisories

No advisories yet.

Fixes

Solution

The vendor fixed the issue in version 24.03.03 (or higher) which can be downloaded from hasomed.de/produkte/elefant/ https://hasomed.de/produkte/elefant/ or via the Elefant Software Updater.


Workaround

While workarounds such as modifying the Elefant windows firewall rules and manually adjusting file permissions in the installation folder are feasible workarounds for some of the vulnerabilities, it is recommended to install the patches provided by the vendor.

History

Mon, 03 Nov 2025 23:30:00 +0000

Type Values Removed Values Added
References

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00149}

epss

{'score': 0.00173}


Fri, 08 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Hasomed
Hasomed elefant
CPEs cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:*
Vendors & Products Hasomed
Hasomed elefant
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 08:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM").
Title Unprotected Exposed Firebird Database with default credentials
Weaknesses CWE-1393
CWE-419
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-11-03T22:28:24.055Z

Reserved: 2024-10-25T07:26:12.628Z

Link: CVE-2024-50588

cve-icon Vulnrichment

Updated: 2025-11-03T22:28:24.055Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T09:15:07.680

Modified: 2025-11-03T23:17:13.390

Link: CVE-2024-50588

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.