VYPR

Elefant

by Hasomed

CVEs (3)

  • CVE-2024-50591HigNov 8, 2024
    risk 0.51cvss 7.8epss 0.02

    An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the…

  • CVE-2024-50589HigNov 8, 2024
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated attacker with access to the local network of the medical office can query an unprotected Fast Healthcare Interoperability Resources (FHIR) API to get access to sensitive electronic health records (EHR).

  • CVE-2024-50592HigNov 8, 2024
    risk 0.46cvss 7.0epss 0.00

    An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process. When using the repair function, the service…