Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.
References
| Link | Resource |
|---|---|
| https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01 | Mitigation Third Party Advisory US Government Resource |
| https://www.vertikalsystems.com/en/products/pm/contact.php | Product |
Configurations
History
06 Nov 2025, 19:20
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Vertikalsystems
Vertikalsystems hospital Manager Backend Services |
|
| CPE | cpe:2.3:a:vertikalsystems:hospital_manager_backend_services:*:*:*:*:*:*:*:* | |
| References | () https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01 - Mitigation, Third Party Advisory, US Government Resource | |
| References | () https://www.vertikalsystems.com/en/products/pm/contact.php - Product |
29 Oct 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-29 22:15
Updated : 2025-11-06 19:20
NVD link : CVE-2025-61959
Mitre link : CVE-2025-61959
CVE.ORG link : CVE-2025-61959
JSON object : View
Products Affected
vertikalsystems
- hospital_manager_backend_services
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
