Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42892


A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow directory listing in any folder accessible to the account assigned to the website’s application pool.


Published

2022-11-17T17:15:12.880

Last Modified

2025-04-30T15:15:57.157

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-23
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens syngo_dynamics_cardiovascular_imaging_and_information_system < va40g_hf01 Yes

References