Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42732


A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper read access control that could allow files to be retrieved from any folder accessible to the account assigned to the website’s application pool.


Published

2022-11-17T17:15:11.673

Last Modified

2025-04-29T21:15:49.620

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-73
  • Type: Primary
    CWE-610

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens syngo_dynamics_cardiovascular_imaging_and_information_system < va40g_hf01 Yes

References