CVE-2025-35031 - CVE House
Back to Database
Status published Medium CVE-2025-35031

Medical Informatics Engineering Enterprise Health includes session token in debug output

Vulnerability Description

Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-35031

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • George Thompson, Sandia National Laboratories
  • Trevor LaPay, Sandia National Laboratories
  • Fernando Martinez, Sandia National Laboratories
  • Gary Huang, Sandia National Laboratories

Affected Vendor

Medical Informatics Engineering

View all reports →

Affected Software

Enterprise Health
Vulnerable Versions:
RC202503, RC202409, RC202403, RC202503 2025-04-08, RC202409 2025-04-08, RC202403 2025-04-08

Timeline

Official Publish: September 29th, 2025
Last Modified: September 30th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.