Cyber Posture

CVE-2024-53522

High

Published: 07 January 2025

Published
07 January 2025
Modified
15 April 2026
KEV Added
Patch
CVSS Score 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0096 76.6th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.

Security Summary

CVE-2024-53522, published on 2025-01-07, affects Bangkok Medical Software HOSxP XE version 4.64.11.3. The vulnerability involves a hardcoded IDEA Key-IV pair within the HOSxPXE4.exe executable and HOS-WIN32.INI components, classified under CWE-331. This cryptographic weakness enables attackers to access sensitive information, earning a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).

Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity and no user interaction required. Exploitation allows them to leverage the exposed Key-IV pair to decrypt protected data, resulting in high-impact confidentiality loss without affecting integrity or availability.

Advisories and further details are available from referenced sources including http://bangkok.com, http://hosxp.com, http://hosxp.net, and https://www.safecloud.co.th/researches/blog/CVE-2024-53522.

Details

CWE(s)
CWE-331

References