CVE-2021-40375

MEDIUMCVSS 6.5/10EPSS 1.62%

Last modified

CVE-2021-40375 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. EPSS estimates a 1.62% chance of exploitation in the next 30 days.

Description

Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
1.62%

73.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AppertaOpeneyes3.5.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-40375?
Apperta Foundation OpenEyes 3.5.1 allows remote attackers to view the sensitive information of patients without having the intended level of privilege. Despite OpenEyes returning a Forbidden error message, the contents of a patient's profile are still returned in the server response. This response can be read in an intercepting proxy or by viewing the page source. Sensitive information returned in responses includes patient PII and medication records or history.
How severe is CVE-2021-40375?
CVE-2021-40375 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.62% probability of exploitation in the next 30 days.
How do I fix CVE-2021-40375?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-40375?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST