CVE-2024-53522
Published: 07 January 2025
Description
Bangkok Medical Software HOSxP XE v4.64.11.3 was discovered to contain a hardcoded IDEA Key-IV pair in the HOSxPXE4.exe and HOS-WIN32.INI components. This allows attackers to access sensitive information.
Security Summary
CVE-2024-53522, published on 2025-01-07, affects Bangkok Medical Software HOSxP XE version 4.64.11.3. The vulnerability involves a hardcoded IDEA Key-IV pair within the HOSxPXE4.exe executable and HOS-WIN32.INI components, classified under CWE-331. This cryptographic weakness enables attackers to access sensitive information, earning a CVSS v3.1 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
Unauthenticated attackers can exploit this vulnerability remotely over the network with low attack complexity and no user interaction required. Exploitation allows them to leverage the exposed Key-IV pair to decrypt protected data, resulting in high-impact confidentiality loss without affecting integrity or availability.
Advisories and further details are available from referenced sources including http://bangkok.com, http://hosxp.com, http://hosxp.net, and https://www.safecloud.co.th/researches/blog/CVE-2024-53522.
Details
- CWE(s)