CVE-2024-50589
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
08/11/2024
Last modified:
03/11/2025
Description
An unauthenticated attacker with access to the local network of the <br />
medical office can query an unprotected Fast Healthcare Interoperability<br />
Resources (FHIR) API to get access to sensitive electronic health <br />
records (EHR).
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH



