9.8

CVE-2022-29875

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensMagnetom Numaris X Firmware Versionva10b
   SiemensMagnetom Numaris X Version-
SiemensMagnetom Numaris X Firmware Versionva12m
   SiemensMagnetom Numaris X Version-
SiemensMagnetom Numaris X Firmware Versionva12s
   SiemensMagnetom Numaris X Version-
SiemensMagnetom Numaris X Firmware Versionva20a
   SiemensMagnetom Numaris X Version-
SiemensMagnetom Numaris X Firmware Versionva30a
   SiemensMagnetom Numaris X Version-
SiemensMagnetom Numaris X Firmware Versionva31a
   SiemensMagnetom Numaris X Version-
SiemensMammomat Revelation Firmware Version >= vc20 < vc20d
   SiemensMammomat Revelation Version-
SiemensNaeotom Alpha Firmware Versionva40 Update-
   SiemensNaeotom Alpha Version-
SiemensSomatom X.Cite Firmware Version < va30
   SiemensSomatom X.Cite Version-
SiemensSomatom X.Cite Firmware Versionva30 Update-
   SiemensSomatom X.Cite Version-
SiemensSomatom X.Cite Firmware Versionva40 Update-
   SiemensSomatom X.Cite Version-
SiemensSomatom X.Creed Firmware Version < va30
   SiemensSomatom X.Creed Version-
SiemensSomatom X.Creed Firmware Versionva30 Update-
   SiemensSomatom X.Creed Version-
SiemensSomatom X.Creed Firmware Versionva40 Update-
   SiemensSomatom X.Creed Version-
SiemensSomatom Go.All Firmware Version < va30
   SiemensSomatom Go.All Version-
SiemensSomatom Go.All Firmware Versionva30 Update-
   SiemensSomatom Go.All Version-
SiemensSomatom Go.All Firmware Versionva40 Update-
   SiemensSomatom Go.All Version-
SiemensSomatom Go.Now Firmware Version < va30
   SiemensSomatom Go.Now Version-
SiemensSomatom Go.Now Firmware Versionva30 Update-
   SiemensSomatom Go.Now Version-
SiemensSomatom Go.Now Firmware Versionva40 Update-
   SiemensSomatom Go.Now Version-
SiemensSomatom Go.Open Pro Firmware Version < va30
   SiemensSomatom Go.Open Pro Version-
SiemensSomatom Go.Open Pro Firmware Versionva30 Update-
   SiemensSomatom Go.Open Pro Version-
SiemensSomatom Go.Open Pro Firmware Versionva40 Update-
   SiemensSomatom Go.Open Pro Version-
SiemensSomatom Go.Sim Firmware Version < va30
   SiemensSomatom Go.Sim Version-
SiemensSomatom Go.Sim Firmware Versionva30 Update-
   SiemensSomatom Go.Sim Version-
SiemensSomatom Go.Sim Firmware Versionva40 Update-
   SiemensSomatom Go.Sim Version-
SiemensSomatom Go.Up Firmware Version < va30
   SiemensSomatom Go.Up Version-
SiemensSomatom Go.Up Firmware Versionva30 Update-
   SiemensSomatom Go.Up Version-
SiemensSomatom Go.Up Firmware Versionva40 Update-
   SiemensSomatom Go.Up Version-
SiemensSymbia E Firmware Version >= vb22 < vb22a-ud03
   SiemensSymbia E Version-
SiemensSymbia S Firmware Version >= vb22 < vb22a-ud03
   SiemensSymbia S Version-
SiemensSymbia Evo Firmware Version >= vb22 < vb22a-ud03
   SiemensSymbia Evo Version-
SiemensSymbia Intevo Firmware Version >= vb22 < vb22a-ud03
   SiemensSymbia Intevo Version-
SiemensSymbia T Firmware Version >= vb22 < vb22a-ud03
   SiemensSymbia T Version-
SiemensSymbia.Net Version >= vb22 <= vb22a-ud03
SiemensSyngo.Via Version >= vb40 < vb40b
SiemensSyngo.Via Version >= vb60 < vb60b
SiemensSyngo.Via Versionvb10
SiemensSyngo.Via Versionvb20
SiemensSyngo.Via Versionvb30
SiemensSyngo.Via Versionvb40b Update-
SiemensSyngo.Via Versionvb50
SiemensSyngo.Via Versionvb60b Update-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.37% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-502 Deserialization of Untrusted Data

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.