Epic Systems develops widely deployed healthcare information systems, including its EpicCare clinical platform and MyChart patient portal, that integrate deeply into hospital networks and patient workflows. Vulnerabilities affecting the vendor center on its core products and have been characterized by XML injection and related data-parsing issues, reflecting the complexity of healthcare data interchange and authentication mechanisms. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Epic over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-6272HIGH XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic p | Feb 20, 2018 | 7.5 | 38 | NO | YES |
CVE-2003-0328HIGH EPIC IRC Client (EPIC4) pre2.002, pre2.003, and possibly later versions, allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary cod | Jun 9, 2003 | 7.5 | 32 | NO | YES |
CVE-2003-0324HIGH Buffer overflows in EPIC IRC Client (EPIC4) 1.0.1 allows remote malicious IRC servers to cause a denial of service (crash) and possibly execute arbitrary code via long replies that | Jun 9, 2003 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Epic.
Media articles that mention a CVE ID that affects a product developed by Epic — matched by CVE ID, not by vendor name.