Vulnerabilities Identified in Hospital Management Solution from Vertical Systems

A hospital management system from the Romanian company, Vertical Systems, has two vulnerabilities that could, if exploited, put sensitive patient information at risk. Hospital Manager Backend Services is used by hospitals to manage a range of backend operations, and vulnerabilities put patient data at risk.

The most serious vulnerability is a high-severity flaw that exposed the ASP.NET tracing endpoint /trace.axd without authentication. The exposed endpoint could allow a remote attacker to obtain live request traces and sensitive data, which may include internal file paths, session identifiers, and metadata. The vulnerability has been assigned a CVSS v4 base score of 8.7, and is tracked as CVE-2025-54459.

The second issue is a medium-severity flaw, tracked as CVE-2025-61959, which has a CVSS v4 base score of 6.9. The flaw resulted verbose ASP.NET error pages for invalid WebResource.axd requests, disclosing framework and ASP.NET version information, stack traces, internal paths, and the insecure configuration ‘customErrors mode=’Off”, which could have facilitated reconnaissance by unauthenticated attackers.

Vertikal Systems has fixed both flaws in its September 19, 2025, release, and the fixes will be present in future releases. The Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory about the two vulnerabilities, which can be exploited remotely in a low-complexity attack. At the time the advisory was issued, CISA was unaware of any instances of exploitation of the vulnerabilities in the wild. Customers have been advised to contact Vertikal Systems for assistance with remediating the vulnerabilities.

While ensuring that the latest release is used, healthcare organizations can reduce the risk of exploitation of vulnerabilities by minimizing network exposure for all control system devices and isolating control systems from business networks. If remote access is required, then a secure method of connecting should be used, such as an up-to-date Virtual Private Network (VPN).

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/