PT-2022-24557 · Canon Medical Informatics · Vitrea Vision

CVE-2022-38765

·

Published

2022-12-08

·

Updated

2022-12-12

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Canon Medical Informatics Vitrea Vision version 7.7.76.1
Description The issue is related to inadequate access control enforcement, allowing an authenticated user to gain unauthorized access to imaging records. This can be achieved by tampering with the patientId parameter in the "vitrea-view/studies/search" API endpoint.
Recommendations For Canon Medical Informatics Vitrea Vision version 7.7.76.1, consider restricting access to the "vitrea-view/studies/search" API endpoint until a patch is available. As a temporary workaround, avoid using the patientId parameter in this endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-38765

Affected Products

Vitrea Vision