Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations.
This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.
References
Link | Resource |
---|---|
https://cert.pl/en/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
https://cert.pl/posts/2024/06/CVE-2024-1228/ | Third Party Advisory |
Configurations
History
12 Jun 2024, 17:51
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:estomed:simple_care:*:*:*:*:*:*:*:* | |
References | () https://cert.pl/en/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
References | () https://cert.pl/posts/2024/06/CVE-2024-1228/ - Third Party Advisory | |
First Time |
Estomed simple Care
Estomed |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
Summary |
|
10 Jun 2024, 12:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-10 12:15
Updated : 2024-06-12 17:51
NVD link : CVE-2024-3700
Mitre link : CVE-2024-3700
CVE.ORG link : CVE-2024-3700
JSON object : View
Products Affected
estomed
- simple_care
CWE
CWE-798
Use of Hard-coded Credentials