VulnerabilityModified
CVE-2019-17428
An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
MEDIUM 5.9EPSS 0.65%
Does this matter?
Lower severity and a low EPSS score (0.65%). Track it; it rarely justifies an emergency change on its own.
Description
An issue was discovered in Intesync Solismed 3.3sp1. An flaw in the encryption implementation exists, allowing for all encrypted data stored within the database to be decrypted.
- CVSS 3.1
- 5.9 MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.65% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-327
- Affected
- intesync/solismed
- Source
- cve@mitre.org
References
- https://know.bishopfox.com/advisoriesThird Party Advisory
- https://know.bishopfox.com/advisories/solismed-criticalExploit, Third Party Advisory
- https://www.solismed.com/Product
- https://know.bishopfox.com/advisoriesThird Party Advisory
- https://know.bishopfox.com/advisories/solismed-criticalExploit, Third Party Advisory
- https://www.solismed.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.