Description
Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.
Problem types
CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Product status
Any version
Credits
Pundhapat Sichamnong reported these vulnerabilities to CISA.
References
www.cisa.gov/...vents/ics-medical-advisories/icsma-25-301-01