CVE-2024-50588
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
08/11/2024
Last modified:
03/11/2025
Description
An unauthenticated attacker with access to the local network of the <br />
medical office can use known default credentials to gain remote DBA <br />
access to the Elefant Firebird database. The data in the database <br />
includes patient data and login credentials among other sensitive data. <br />
In addition, this enables an attacker to create and overwrite arbitrary <br />
files on the server filesystem with the rights of the Firebird database <br />
("NT AUTHORITY\SYSTEM").
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL



