Hard-coded Password Exposes Sensitive Data in drEryk Gabinet Software
CVE-2024-3699

9.3CRITICAL

Key Information:

Vendor
CVE Published:
10 June 2024

What is CVE-2024-3699?

A security vulnerability exists in drEryk Gabinet software due to the use of a hard-coded password, which poses a significant threat to the confidentiality of patient data stored in its database. All installations of drEryk Gabinet from version 7.0.0.0 to 9.17.0.0 utilize the same password, leaving the sensitive data vulnerable to unauthorized access. This flaw can potentially allow attackers to retrieve and exploit confidential patient information, emphasizing the urgent need for a security update to eliminate hard-coded credentials in the software.

Affected Version(s)

drEryk Gabinet 7.0.0.0 <= 9.17.0.0.

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.