PT-2022-24557 · Canon Medical Informatics · Vitrea Vision

Published

2022-12-08

·

Updated

2022-12-12

·

CVE-2022-38765

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Canon Medical Informatics Vitrea Vision version 7.7.76.1
Description The issue is related to inadequate access control enforcement, allowing an authenticated user to gain unauthorized access to imaging records. This can be achieved by tampering with the patientId parameter in the "vitrea-view/studies/search" API endpoint.
Recommendations For Canon Medical Informatics Vitrea Vision version 7.7.76.1, consider restricting access to the "vitrea-view/studies/search" API endpoint until a patch is available. As a temporary workaround, avoid using the patientId parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-38765

Affected Products

Vitrea Vision