Hardcoded Service Password
Vulnerability Description
An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-50593
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Tobias Niemann, SEC Consult Vulnerability Lab
- Daniel Hirschberger, SEC Consult Vulnerability Lab
- Florian Stuhlmann, SEC Consult Vulnerability Lab
More from HASOMED
View All →Affected Vendor
HASOMED
View all reports →