Executive brief
Callvision Emergency Code, a healthcare communication system used for managing emergency alerts, contains a critical security flaw. An attacker can remotely access and manipulate the underlying database without needing a username or password. This could lead to the theft of sensitive patient data, disruption of emergency response services, or unauthorized modification of critical healthcare records.
Technical details
A critical SQL injection vulnerability (CWE-89) exists in Callvision Healthcare Callvision Emergency Code versions prior to V3.0. The application fails to properly neutralize special elements in SQL commands, enabling both standard and blind SQL injection attacks. This vulnerability is exploitable over the network without authentication (AV:N/AC:L/PR:N/UI:N), allowing an attacker to execute arbitrary SQL queries. Successful exploitation can result in full unauthorized access to, modification of, or deletion of data within the application's database. Users are advised to upgrade to version V3.0 or later to remediate this issue.
Affected products
- Callvision Healthcare Callvision Emergency Code before V3.0
Timeline
- 2025-10-07: disclosed: Initial publication of the vulnerability advisory.
- 2025-10-07: advisory: NVD and USOM published details regarding CVE-2025-0603.