Vulnerabilities > CVE-2022-38765 - Authorization Bypass Through User-Controlled Key vulnerability in Canon Vitrea View

047910
CVSS 6.5 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
canon
CWE-639

Summary

Canon Medical Informatics Vitrea Vision 7.7.76.1 does not adequately enforce access controls. An authenticated user is able to gain unauthorized access to imaging records by tampering with the vitrea-view/studies/search patientId parameter.

Vulnerable Configurations

Part Description Count
Application
Canon
1