CVE-2024-50589

HIGH

HASOMED Elefant < 24.04.00 - Unauthenticated Sensitive Data Exposure via FHIR API

Title source: llm
STIX 2.1

Description

An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).

References (3)

Core 3
Core References
Various Sources third-party-advisory
https://r.sec-consult.com/hasomed
Various Sources patch
https://hasomed.de/produkte/elefant/

Scores

CVSS v3 7.5
EPSS 0.0056
EPSS Percentile 42.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (1)
HASOMED/Elefant <24.04.00
Published Nov 08, 2024
Tracked Since Feb 18, 2026