Vulnerabilities Identified in Hospital Management Solution from Vertical Systems
A hospital management system from the Romanian company, Vertical Systems, has two vulnerabilities that could, if exploited, put sensitive patient information at risk. Hospital Manager Backend Services is used by hospitals to manage a range of backend operations, and vulnerabilities put patient data at risk.
The most serious vulnerability is a high-severity flaw that exposed the ASP.NET tracing endpoint /trace.axd without authentication. The exposed endpoint could allow a remote attacker to obtain live request traces and sensitive data, which may include internal file paths, session identifiers, and metadata. The vulnerability has been assigned a CVSS v4 base score of 8.7, and is tracked as CVE-2025-54459.
The second issue is a medium-severity flaw, tracked as CVE-2025-61959, which has a CVSS v4 base score of 6.9. The flaw resulted verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration ‘customErrors mode=’Off”, which could have facilitated reconnaissance by unauthenticated attackers.
Vertikal Systems has fixed both flaws in its September 19, 2025, release, and the fixes will be present in future releases. The Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory about the two vulnerabilities, which can be exploited remotely in a low-complexity attack. At the time the advisory was issued, CISA was unaware of any instances of exploitation of the vulnerabilities in the wild. Customers have been advised to contact Vertikal Systems for assistance with remediating the vulnerabilities.
While ensuring that the latest release is used, healthcare organizations can reduce the risk of exploitation of vulnerabilities by minimizing network exposure for all control system devices and isolating control systems from business networks. If remote access is required, then a secure method of connecting should be used, such as an up-to-date Virtual Private Network (VPN).