Medhost develops a focused portfolio of healthcare information systems and electronic health record platforms, including products such as Connex and its perioperative and document-management offerings that serve hospital and surgical-facility operations. The durable signal in its disclosures centers on hard-coded credentials and related authentication weaknesses, a class that reflects the legacy architecture and integration constraints typical of healthcare software deployed across clinical environments. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Medhost over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11743CRITICAL MEDHOST Connex contains a hard-coded Mirth Connect admin credential that is used for customer Mirth Connect management access. An attacker with knowledge of the hard-coded credenti | Jul 31, 2017 | 9.8 | 30 | NO | NO |
CVE-2016-4328CRITICAL MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which makes it easier for remote attackers to obtain sensitive info | Jun 10, 2016 | 9.8 | 30 | NO | NO |
CVE-2017-11694CRITICAL MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to | Jul 28, 2017 | 9.1 | 26 | NO | NO |
CVE-2017-11614CRITICAL MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate d | Jul 25, 2017 | 9.8 | 24 | NO | NO |
CVE-2017-11693CRITICAL MEDHOST Document Management System contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the abil | Jul 28, 2017 | 9.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Medhost.
Media articles that mention a CVE ID that affects a product developed by Medhost — matched by CVE ID, not by vendor name.