An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).
History

Fri, 08 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Hasomed
Hasomed elefant
CPEs cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:*
Vendors & Products Hasomed
Hasomed elefant
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 11:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).
Title Unprotected FHIR API
Weaknesses CWE-306
References

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published: 2024-11-08T11:34:33.967Z

Updated: 2024-11-08T15:31:49.333Z

Reserved: 2024-10-25T07:26:12.628Z

Link: CVE-2024-50589

cve-icon Vulnrichment

Updated: 2024-11-08T15:30:23.979Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T12:15:14.707

Modified: 2024-11-08T19:01:03.880

Link: CVE-2024-50589

cve-icon Redhat

No data.