VulnerabilityModified
CVE-2024-1228
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database.
CRITICAL 9.3EPSS 0.41%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations. This issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed).
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-259, CWE-798
- Affected
- eurosoft/przychodnia
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://www.eurosoft.com.pl/eurosoft-przychodniaProduct
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://www.eurosoft.com.pl/eurosoft-przychodniaProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.