CVE-2024-50589

An unauthenticated attacker with access to the local network of the 
medical office can query an unprotected Fast Healthcare Interoperability
 Resources (FHIR) API to get access to sensitive electronic health 
records (EHR).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
SEC-VLabCNA
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N