An attacker with local access to the medical office computer can access restricted functions of the Elefant Service tool by using a hard-coded "Hotline" password in the Elefant service binary, which is shipped with the software.
Solution:
Workaround:
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://r.sec-consult.com/hasomed | third party advisory |
https://hasomed.de/produkte/elefant/ | patch |