An attacker with local access to the medical office computer can
access restricted functions of the Elefant Service tool by using a
hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
Metrics
Affected Vendors & Products
References
History
Fri, 08 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Hasomed
Hasomed elefant |
|
CPEs | cpe:2.3:a:hasomed:elefant:*:*:*:*:*:*:*:* | |
Vendors & Products |
Hasomed
Hasomed elefant |
|
Metrics |
cvssV3_1
|
Fri, 08 Nov 2024 12:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software. | |
Title | Hardcoded Service Password | |
Weaknesses | CWE-798 | |
References |
|
MITRE
Status: PUBLISHED
Assigner: SEC-VLab
Published: 2024-11-08T12:06:28.619Z
Updated: 2024-11-08T15:41:42.624Z
Reserved: 2024-10-25T07:26:12.628Z
Link: CVE-2024-50593
Vulnrichment
Updated: 2024-11-08T15:41:35.498Z
NVD
Status : Awaiting Analysis
Published: 2024-11-08T12:15:15.037
Modified: 2024-11-08T19:01:03.880
Link: CVE-2024-50593
Redhat
No data.