Vulnerability Description
Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and sensitive information such as request metadata, session identifiers, authorization headers, server variables, and internal file paths.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vertikalsystems | Hospital Manager Backend Services | <= 2025-09-19 |
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-301-01MitigationThird Party AdvisoryUS Government Resource
FAQ
What is CVE-2025-54459?
CVE-2025-54459 is a vulnerability with a CVSS score of 7.5 (HIGH). Prior to September 19, 2025, the Hospital Manager Backend Services exposed the ASP.NET tracing endpoint /trace.axd without authentication, allowing a remote attacker to obtain live request traces and ...
How severe is CVE-2025-54459?
CVE-2025-54459 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-54459?
Check the references section above for vendor advisories and patch information. Affected products include: Vertikalsystems Hospital Manager Backend Services.