VulnerabilityModified
CVE-2024-3700
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database.
CRITICAL 9.3EPSS 0.36%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.36%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.
- CVSS 4.0
- 9.3 CRITICALCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.36% probability · 29th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-259, CWE-798
- Affected
- estomed/simple care
- Source
- cvd@cert.pl
References
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/en/posts/2024/06/CVE-2024-1228/Third Party Advisory
- https://cert.pl/posts/2024/06/CVE-2024-1228/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.