{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2024-3700","assignerOrgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","state":"PUBLISHED","assignerShortName":"CERT-PL","dateReserved":"2024-04-12T08:52:16.249Z","datePublished":"2024-06-10T11:19:54.619Z","dateUpdated":"2025-10-03T09:03:38.081Z"},"containers":{"cna":{"affected":[{"defaultStatus":"affected","product":"Simple Care","vendor":"Estomed Sp. z o.o.","versions":[{"status":"affected","version":"all versions"}]}],"datePublic":"2024-06-10T00:00:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<p>Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations.</p><p>This issue affects&nbsp;Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported.</p>"}],"value":"Use of hard-coded password to the patients' database allows an attacker to retrieve sensitive data stored in the database. The password is the same among all Simple Care software installations.\n\nThis issue affects Estomed Sp. z o.o. Simple Care software in all versions. The software is no longer supported."}],"impacts":[{"capecId":"CAPEC-37","descriptions":[{"lang":"en","value":"CAPEC-37 Retrieve Embedded Sensitive Data"}]}],"metrics":[{"cvssV4_0":{"Automatable":"YES","Recovery":"USER","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"LOCAL","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","providerUrgency":"RED","subAvailabilityImpact":"HIGH","subConfidentialityImpact":"NONE","subIntegrityImpact":"HIGH","userInteraction":"NONE","valueDensity":"CONCENTRATED","vectorString":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:H/SA:H/AU:Y/R:U/V:C/RE:M/U:Red","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH","vulnerabilityResponseEffort":"MODERATE"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-259","description":"CWE-259 Use of Hard-coded Password","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"4bb8329e-dd38-46c1-aafb-9bf32bcb93c6","shortName":"CERT-PL","dateUpdated":"2025-10-03T09:03:38.081Z"},"references":[{"tags":["third-party-advisory"],"url":"https://cert.pl/en/posts/2024/06/CVE-2024-1228/"},{"tags":["third-party-advisory"],"url":"https://cert.pl/posts/2024/06/CVE-2024-1228/"}],"source":{"discovery":"EXTERNAL"},"title":"Hardcoded password in Estomed Sp. z o.o. Simple Care software","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-01T20:20:00.769Z"},"title":"CVE Program Container","references":[{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/en/posts/2024/06/CVE-2024-1228/"},{"tags":["third-party-advisory","x_transferred"],"url":"https://cert.pl/posts/2024/06/CVE-2024-1228/"}]},{"affected":[{"vendor":"estomed","product":"simple_care","cpes":["cpe:2.3:a:estomed:simple_care:*:*:*:*:*:*:*:*"],"defaultStatus":"unknown","versions":[{"version":"0","status":"affected","lessThan":"*","versionType":"custom"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2024-09-03T17:34:55.689302Z","id":"CVE-2024-3700","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-09-03T17:43:21.581Z"}}]}}