Description
An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.
Published: 2026-08-17
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can trigger the execution of arbitrary code on the affected system by providing a specially crafted dynamic link library file. This flaw allows the remote execution of code with the privileges of the target application, potentially compromising confidentiality, integrity, and availability of the system. The vulnerability’s core weakness aligns with code injection and execution abuse.

Affected Systems

CompuGroup Medical CGM ISIS MED version 2510.1.0.20. No other affected products or editions are specified.

Risk and Exploitability

The CVE has an EPSS score of <1% and a CVSS score of 7.8, and it is not present in the CISA KEV catalog, indicating a low public exploitation footprint as of the available data. No official mitigation is publicly announced, so the flaw could still be leveraged by attackers who can supply the malicious DLL, typically via remote upload or remote execution channels. The vector is inferred to be remote file manipulation given the nature of the exploit.

Generated by OpenCVE AI on August 21, 2026 at 20:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Verify whether CGM has released an official patch or update for CGM ISIS MED 2510.1.0.20 and apply it if available.
  • Restrict write permissions and execution rights on directories that the application scans for DLLs to prevent unauthorized DLL placement.
  • Deploy monitoring that alerts on the creation or loading of unexpected or unsigned DLL files in those directories.

Generated by OpenCVE AI on August 21, 2026 at 20:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 21:00:00 +0000

Type Values Removed Values Added
Title Arbitrary Code Execution via Crafted DLL in CGM ISIS MED

Fri, 21 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in CGM ISIS MED via Crafted DLL
Weaknesses CWE-94

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-427
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Remote Code Execution in CGM ISIS MED via Crafted DLL
Weaknesses CWE-94

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-18T18:26:17.684Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50773

cve-icon Vulnrichment

Updated: 2026-08-18T18:25:56.502Z

cve-icon NVD

Status : Deferred

Published: 2026-08-17T19:16:31.663

Modified: 2026-08-31T20:12:02.273

Link: CVE-2026-50773

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:45:03Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element