← Back

CVE-2022-38765

nvd nist
Published: Dec 9, 2022Modified: Apr 23, 2025

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

Affected (1)

Products: Canon: Vitrea View
1 product
Vitrea View
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 7.8

Timeline

No history available yet.