Arbitrary Code Execution Vulnerability in Print.pl Service by Vendor XYZ
CVE-2025-2313

9.4CRITICAL

Key Information:

Vendor

Cgm

Vendor
CVE Published:
27 August 2025

What is CVE-2025-2313?

The Print.pl service contains a vulnerability that enables arbitrary code execution through improper handling of the 'CopyCounter' parameter in the 'uhcPrintServerPrint' function. This weakness could allow an attacker to manipulate the parameter and execute malicious code on the server, leading to potential unauthorized access or disruption of service.

Affected Version(s)

CGM CLININET 0 < 2025.MS1

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Maciej Kazulak
.
CVE-2025-2313 : Arbitrary Code Execution Vulnerability in Print.pl Service by Vendor XYZ