Overview
The Epiphany Cardio Server is vulnerable to SQL injection and LDAP injection, allowing an unauthenticated attacker to gain administrator rights.
Description
Epiphany Cardio Server was reported as being vulnerable to the following issues: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') - CVE-2015-6537 |
Impact
An attacker on the local network may be able to bypass authentication, and access and modify patient information. |
Solution
Apply an update |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | 8.3 | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Temporal | 6.5 | E:POC/RL:OF/RC:C |
Environmental | 4.9 | CDP:ND/TD:M/CR:H/IR:H/AR:ND |
References
Acknowledgements
Thanks to Alex Lauerman of TrustFoundry for reporting this vulnerability.
This document was written by Garret Wassermann.
Other Information
CVE IDs: | CVE-2015-6537, CVE-2015-6538 |
Date Public: | 2015-11-30 |
Date First Published: | 2015-12-01 |
Date Last Updated: | 2015-12-09 23:40 UTC |
Document Revision: | 35 |