HASOMED Elefant / Elefant Software Updater Data Exposure / Privilege Escalation ≈ Packet Storm

Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]

HASOMED Elefant / Elefant Software Updater Data Exposure / Privilege Escalation[6]
Authored by Daniel Hirschberger[7], Florian Stuhlmann[8] | Site sec-consult.com[9]

HASOMED Elefant versions prior to 24.04.00 and Elefant Software Updater versions prior to 1.4.2.1811 suffer from having an unprotected exposed firebird database, unprotected FHIR API, multiple local privilege escalation, and hardcoded service password vulnerabilities.

advisories | CVE-2024-50588[10], CVE-2024-50589[11], CVE-2024-50590[12], CVE-2024-50591[13], CVE-2024-50592[14], CVE-2024-50593[15]
SHA-256 | 08569aaf8d9ee2326579f45288b32f5dc1f2f9623687358b993634b1d5424d28

Login[19] or Register[20] to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa

File Tags

File Archives

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services[125]
Hosting By
Rokasec[126]
close
Image

Pensée du jour :

Ce que l'homme a fait ,

l'homme peut le défaire.

 

"No secure path in the world"