Home

Description

The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.

PUBLISHED Reserved 2025-09-01 | Published 2026-03-02 | Updated 2026-03-02 | Assigner CERT-PL




MEDIUM: 5.3CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Problem types

CWE-693 Protection Mechanism Failure

Product status

Default status
unaffected

Any version before 2025.MS3
affected

References

cert.pl/en/posts/2026/03/CVE-2025-10350/ third-party-advisory

www.cgm.com/pol_pl/products/szpital/cgm-clininet.html product

cve.org (CVE-2025-58406)

nvd.nist.gov (CVE-2025-58406)

Download JSON