CVE-2025-54459
7.5Vertikal Systems · Hospital Manager Backend Services
The Hospital Manager Backend Services exposed the ASP.NET trace.axd endpoint to unauthenticated users, allowing the leakage of sensitive request metadata, session identifiers, and server variables.
Executive summary
An unauthenticated information disclosure vulnerability in Vertikal Systems Hospital Manager Backend Services allows remote attackers to harvest sensitive session and system data.
Vulnerability
The application improperly exposes the ASP.NET tracing endpoint, trace.axd, without requiring authentication. This flaw permits remote, unauthenticated attackers to view live request traces containing session identifiers, authorization headers, and internal file paths.
Business impact
The exposure of session identifiers and authorization headers provides attackers with the necessary credentials to hijack user sessions or escalate privileges within the hospital management environment. Given the CVSS score of 7.5, this high severity vulnerability poses a significant risk of unauthorized data access and potential compromise of sensitive medical or administrative records.
Remediation
Immediate Action: Contact Vertikal Systems support to obtain and apply the necessary security updates or configuration changes implemented after September 19, 2025.
Proactive Monitoring: Review web server access logs for anomalous requests directed at the /trace.axd endpoint, which may indicate reconnaissance or exploitation attempts.
Compensating Controls: Implement a Web Application Firewall (WAF) rule to block or restrict access to the /trace.axd endpoint if an immediate software update cannot be deployed.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a critical security oversight that exposes sensitive authentication material to any remote, unauthenticated actor. Organizations utilizing Vertikal Systems Hospital Manager must prioritize verification of their patch status with the vendor immediately. Failure to address this exposure could lead to full system compromise through session hijacking.
Sources
Originally found and disclosed by Pundhapat Sichamnong reported these vulnerabilities to CISA., per the CVE Program record.