RULE(RULE ID:338475)

Rule General Information
Release Date: 2024-10-22
Rule Name: Infinitt Picture Archiving and Communication System WebUserLogin Information Disclosure Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: Infinitt Picture Archiving and Communication System is a system applied in the imaging department of hospitals. Its main task is to save various medical images generated in daily life in a digitalized way through different interfaces and call them up quickly when needed, as well as to provide auxiliary diagnostic management functions. An unauthorized information disclosure vulnerability exists in the WebUserLogin.asmx endpoint of the system, which can cause sensitive user login information to be disclosed.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.