CVE-2022-38765

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/12/2022
Last modified:
23/04/2025

Description

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:canon:vitrea_view:*:*:*:*:*:*:*:* 7.8 (excluding)