6.5
CVSSv3

CVE-2022-38765

Published: 09/12/2022 Updated: 12/12/2022
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

canon vitrea view