CVE-2025-61959
Vertikal Systems Hospital Manager Backend Services Generation of Error Message Containing Sensitive Information
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 6.9EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
29 out 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Prior to September 19, 2025, the Hospital Manager Backend Services returned verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration 'customErrors mode="Off"', which could have facilitated reconnaissance by unauthenticated attackers.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
Produtos afetados
Vertikal Systems · Hospital Manager Backend ServicesQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →