7.5
CVE-2013-6945
- EPSS 1.38%
- Veröffentlicht 04.12.2013 22:55:03
- Zuletzt bearbeitet 29.04.2026 01:13:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The M2M Broker in OSEHRA VistA, as distributed before September 30, 2013, allows attackers to bypass authentication and authorization to perform doctor-only actions and read or modify patient records via unspecified vectors related to a "logic flaw."
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.38% | 0.685 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
http://www.darkreading.com/vulnerability/anatomy-of-an-electronic-health-record-e/240164441/
http://www.osehra.org/blog/m2m-broker-security-patch
http://www.osehra.org/blog/vista-patch-available-osehra