A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Siemens
Subscribe
|
Biograph Horizon Pet\/ct Systems
Subscribe
Biograph Horizon Pet\/ct Systems Firmware
Subscribe
Magnetom Numaris X
Subscribe
Magnetom Numaris X Firmware
Subscribe
Mammomat Revelation
Subscribe
Mammomat Revelation Firmware
Subscribe
Naeotom Alpha
Subscribe
Naeotom Alpha Firmware
Subscribe
Somatom Go.all
Subscribe
Somatom Go.all Firmware
Subscribe
Somatom Go.now
Subscribe
Somatom Go.now Firmware
Subscribe
Somatom Go.open Pro
Subscribe
Somatom Go.open Pro Firmware
Subscribe
Somatom Go.sim
Subscribe
Somatom Go.sim Firmware
Subscribe
Somatom Go.up
Subscribe
Somatom Go.up Firmware
Subscribe
Somatom X.cite
Subscribe
Somatom X.cite Firmware
Subscribe
Somatom X.creed
Subscribe
Somatom X.creed Firmware
Subscribe
Symbia.net
Subscribe
Symbia E
Subscribe
Symbia E Firmware
Subscribe
Symbia Evo
Subscribe
Symbia Evo Firmware
Subscribe
Symbia Intevo
Subscribe
Symbia Intevo Firmware
Subscribe
Symbia S
Subscribe
Symbia S Firmware
Subscribe
Symbia T
Subscribe
Symbia T Firmware
Subscribe
Syngo.via
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-34187 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: siemens
Published:
Updated: 2024-08-03T06:33:42.999Z
Reserved: 2022-04-28T00:00:00
Link: CVE-2022-29875
No data.
Status : Modified
Published: 2022-06-01T10:15:08.197
Modified: 2024-11-21T06:59:52.537
Link: CVE-2022-29875
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD