Security Advisory

CVE-2025-54459

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-29 21:51:34
Last updated 2025-10-30 20:31:36
Assigner icscert
CVSS score 8.7
State PUBLISHED

Description

Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.