CVE-2024-3700

Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations. This issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:estomed:simple_care:*:*:*:*:*:*:*:*

History

12 Jun 2024, 17:51

Type Values Removed Values Added
References () https://cert.pl/en/posts/2024/06/CVE-2024-1228/ - () https://cert.pl/en/posts/2024/06/CVE-2024-1228/ - Third Party Advisory
References () https://cert.pl/posts/2024/06/CVE-2024-1228/ - () https://cert.pl/posts/2024/06/CVE-2024-1228/ - Third Party Advisory
First Time Estomed simple Care
Estomed
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
Summary
  • (es) El uso de una contraseña codificada para la base de datos de los pacientes permite a un atacante recuperar datos confidenciales almacenados en la base de datos. La contraseña es la misma en todas las instalaciones del software Simple Care. Este problema afecta a Estomed Sp. z o.o. Software z oo Simple Care en todas las versiones. El software ya no es compatible.
CPE cpe:2.3:a:estomed:simple_care:*:*:*:*:*:*:*:*

10 Jun 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-10 12:15

Updated : 2024-06-12 17:51


NVD link : CVE-2024-3700

Mitre link : CVE-2024-3700

CVE.ORG link : CVE-2024-3700


JSON object : View

Products Affected

estomed

  • simple_care
CWE
CWE-798

Use of Hard-coded Credentials