CVE-2024-50588

An unauthenticated attacker with access to the local network of the medical office can use known default credentials to gain remote DBA access to the Elefant Firebird database. The data in the database includes patient data and login credentials among other sensitive data. In addition, this enables an attacker to create and overwrite arbitrary files on the server filesystem with the rights of the Firebird database ("NT AUTHORITY\SYSTEM").
Configurations

No configuration.

History

No history.

Information

Published : 2024-11-08 09:15

Updated : 2024-11-08 19:01


NVD link : CVE-2024-50588

Mitre link : CVE-2024-50588

CVE.ORG link : CVE-2024-50588


JSON object : View

Products Affected

No product.

CWE
CWE-419

Unprotected Primary Channel

CWE-1393

Use of Default Password