CVE Database
/

CVE-2022-29875

Back to search

CVE-2022-29875

Published: Jun 1, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

VendorProductVersions

Siemens

Biograph Horizon PET/CT Systems

affected
All VJ30 versions < VJ30C-UD01

Siemens

MAGNETOM Family

affected
NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A

Siemens

MAMMOMAT Revelation

affected
All VC20 versions < VC20D

Siemens

NAEOTOM Alpha

affected
All VA40 versions < VA40 SP2

Siemens

SOMATOM X.cite

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM X.creed

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.All

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.Now

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.Open Pro

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.Sim

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.Top

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

SOMATOM go.Up

affected
All versions < VA30 SP5 or VA40 SP2

Siemens

Symbia E/S

affected
All VB22 versions < VB22A-UD03

Siemens

Symbia Evo

affected
All VB22 versions < VB22A-UD03

Siemens

Symbia Intevo

affected
All VB22 versions < VB22A-UD03

Siemens

Symbia T

affected
All VB22 versions < VB22A-UD03

Siemens

Symbia.net

affected
All VB22 versions < VB22A-UD03

Siemens

syngo.via VB10

affected
All versions

Siemens

syngo.via VB20

affected
All versions

Siemens

syngo.via VB30

affected
All versions

Siemens

syngo.via VB40

affected
All versions < VB40B HF06

Siemens

syngo.via VB50

affected
All versions

Siemens

syngo.via VB60

affected
All versions < VB60B HF02

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now