CVE-2024-50589

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
08/11/2024
Last modified:
03/11/2025

Description

An unauthenticated attacker with access to the local network of the <br /> medical office can query an unprotected Fast Healthcare Interoperability<br /> Resources (FHIR) API to get access to sensitive electronic health <br /> records (EHR).