An unauthenticated attacker with access to the local network of the
medical office can query an unprotected Fast Healthcare Interoperability
Resources (FHIR) API to get access to sensitive electronic health
records (EHR).
Advisories

No advisories yet.

Fixes

Solution

The vendor fixed the issue in version 24.04.00 (or higher) which can be downloaded from hasomed.de/produkte/elefant/ https://hasomed.de/produkte/elefant/ or via the Elefant Software Updater.


Workaround

While workarounds such as modifying the Elefant windows firewall rules and manually adjusting file permissions in the installation folder are feasible workarounds for some of the vulnerabilities, it is recommended to install the patches provided by the vendor.

History

Mon, 03 Nov 2025 23:30:00 +0000

Type Values Removed Values Added
References

Mon, 14 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00109}

epss

{'score': 0.00119}


Fri, 08 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Hasomed
Hasomed elefant
CPEs cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:*
Vendors & Products Hasomed
Hasomed elefant
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 08 Nov 2024 11:45:00 +0000

Type Values Removed Values Added
Description An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).
Title Unprotected FHIR API
Weaknesses CWE-306
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: SEC-VLab

Published:

Updated: 2025-11-03T22:28:25.537Z

Reserved: 2024-10-25T07:26:12.628Z

Link: CVE-2024-50589

cve-icon Vulnrichment

Updated: 2024-11-08T15:30:23.979Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-08T12:15:14.707

Modified: 2025-11-03T23:17:13.593

Link: CVE-2024-50589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses