CVE-2013-6945 Information

Description

The M2M Broker in OSEHRA VistA as distributed before September 30 2013 allows attackers to bypass authentication and authorization to perform doctor-only actions and read or modify patient records via unspecified vectors related to a \logic flaw.\

Reference

http://www.darkreading.com/vulnerability/anatomy-of-an-electronic-health-record-e/240164441/ http://www.osehra.org/blog/m2m-broker-security-patch http://www.osehra.org/blog/vista-patch-available-osehra

Share on: