Improper Access Control in syngo Dynamics by Siemens Healthineers
CVE-2022-42733
7.5HIGH
Summary
A vulnerability exists in syngo Dynamics where improper read access control in the web service may allow unauthorized access to files from any folder that is accessible to the account used by the website's application pool. This could lead to potential data exposure, compromising sensitive information.
Affected Version(s)
syngo Dynamics All versions < VA40G HF01
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved