{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-1228","assignerOrgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","state":"PUBLISHED","assignerShortName":"CERT-PL","dateReserved":"2024-02-05T13:46:45.179Z","datePublished":"2024-06-10T11:13:44.453Z","dateUpdated":"2025-10-07T13:21:10.928Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Eurosoft Przychodnia","vendor":"EuroSoft Sp. z o. o.","versions":[{"lessThan":"20240417.001","status":"affected","version":"0","versionType":"custom"}]}],"datePublic":"2024-06-10T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations.<br><br><div><p>This issue affects Eurosoft Przychodnia software before&nbsp;<span style=\"background-color: rgb(255, 255, 255);\">version</span>&nbsp;20240417.001 (from that version vulnerability is fixed).</p></div>"}],"value":"Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Eurosoft Przychodnia installations.\n\nThis issue affects Eurosoft Przychodnia software before version 20240417.001 (from that version vulnerability is fixed)."}],"impacts":[{"capecId":"CAPEC-37","descriptions":[{"lang":"en","value":"CAPEC-37 Retrieve Embedded Sensitive Data"}]}],"metrics":[{"cvssV4_0":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/AU:Y/R:U/V:C/RE:M/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-259","description":"CWE-259 Use of Hard-coded Password","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","shortName":"CERT-PL","dateUpdated":"2025-10-03T09:00:16.189Z"},"references":[{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2024/06/CVE-2024-1228/"},{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2024/06/CVE-2024-1228/"},{"tags":["product"],"url":"https://www.eurosoft.com.pl/eurosoft-przychodnia"}],"source":{"discovery":"EXTERNAL"},"title":"Hardcoded password in Eurosoft Przychodnia","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"affected":[{"vendor":"eurosoftsp.zo.o","product":"eurosoft_przychodina","cpes":["cpe:2.3:a:eurosoftsp.zo.o:eurosoft_przychodina:20240417.001:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"20240417.001","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-06-10T13:42:43.489051Z","id":"CVE-2024-1228","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-10-07T13:21:10.928Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T18:33:25.114Z"},"title":"CVE Program Container","references":[{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/en/posts/2024/06/CVE-2024-1228/"},{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/posts/2024/06/CVE-2024-1228/"},{"tags":["product","x_transferred"],"url":"https://www.eurosoft.com.pl/eurosoft-przychodnia"}]}]}}