Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-42893


A vulnerability has been identified in syngo Dynamics (All versions < VA40G HF01). syngo Dynamics application server hosts a web service using an operation with improper write access control that could allow to write data in any folder accessible to the account assigned to the website’s application pool.


Published

2022-11-17T17:15:13.207

Last Modified

2025-04-30T15:15:57.337

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-73
  • Type: Primary
    CWE-610

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application siemens syngo_dynamics_cardiovascular_imaging_and_information_system < va40g_hf01 Yes

References