medical office can use known default credentials to gain remote DBA
access to the Elefant Firebird database. The data in the database
includes patient data and login credentials among other sensitive data.
In addition, this enables an attacker to create and overwrite arbitrary
files on the server filesystem with the rights of the Firebird database
("NT AUTHORITY\SYSTEM").
Metrics
Affected Vendors & Products
No advisories yet.
Solution
The vendor fixed the issue in version 24.03.03 (or higher) which can be downloaded from hasomed.de/produkte/elefant/ https://hasomed.de/produkte/elefant/ or via the Elefant Software Updater.
Workaround
While workarounds such as modifying the Elefant windows firewall rules and manually adjusting file permissions in the installation folder are feasible workarounds for some of the vulnerabilities, it is recommended to install the patches provided by the vendor.
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| References | 
         | 
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Fri, 08 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Hasomed
         Hasomed elefant  | 
|
| CPEs | cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Hasomed
         Hasomed elefant  | 
|
| Metrics | 
        
        cvssV3_1
         
 
  | 
Fri, 08 Nov 2024 08:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM"). | |
| Title | Unprotected Exposed Firebird Database with default credentials | |
| Weaknesses | CWE-1393 CWE-419  | 
|
| References | 
         | 
Status: PUBLISHED
Assigner: SEC-VLab
Published:
Updated: 2025-11-03T22:28:24.055Z
Reserved: 2024-10-25T07:26:12.628Z
Link: CVE-2024-50588
Updated: 2025-11-03T22:28:24.055Z
Status : Awaiting Analysis
Published: 2024-11-08T09:15:07.680
Modified: 2025-11-03T23:17:13.390
Link: CVE-2024-50588
No data.
                        OpenCVE Enrichment
                    No data.