CVE-2025-35031
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-29

Last updated on: 2026-01-02

Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government

Description
Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. An attacker could convince a user to send this output to the attacker, thus allowing the attacker to impersonate that user. This issue is fixed as of 2025-04-08.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-29
Last Modified
2026-01-02
Generated
2026-06-16
AI Q&A
2025-09-29
EPSS Evaluated
2026-06-14
NVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
mieweb enterprise_health rc202403
mieweb enterprise_health rc202409
mieweb enterprise_health rc202503
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1295 The product fails to adequately prevent the revealing of unnecessary and potentially sensitive system information within debugging messages.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability occurs because Medical Informatics Engineering Enterprise Health includes the user's current session token in debug output. If an attacker convinces a user to send this debug output to them, the attacker can use the session token to impersonate that user.

Impact Analysis

The vulnerability can allow an attacker to impersonate a user by obtaining their session token from debug output. This could lead to unauthorized access to the user's account or sensitive information.

Mitigation Strategies

The vulnerability is fixed as of 2025-04-08. Immediate steps include updating Medical Informatics Engineering Enterprise Health software to the fixed version released on or after 2025-04-08 to prevent exposure of session tokens in debug output.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-35031. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart