CVE-2024-50593

An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
Configurations

No configuration.

History

08 Nov 2024, 16:35

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
Summary
  • (es) Un atacante con acceso local a el ordenador del consultorio médico puede acceder a funciones restringidas de la herramienta de servicio Elefant mediante el uso de una contraseña de "línea directa" codificada en el binario del servicio Elefant, que se envía con el software.

08 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-08 12:15

Updated : 2024-11-08 19:01


NVD link : CVE-2024-50593

Mitre link : CVE-2024-50593

CVE.ORG link : CVE-2024-50593


JSON object : View

Products Affected

No product.

CWE
CWE-798

Use of Hard-coded Credentials