CVE-2022-29875

Description

A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40 SP2), SOMATOM X.creed (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.All (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Now (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Open Pro (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Sim (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Top (All versions < VA30 SP5 or VA40 SP2), SOMATOM go.Up (All versions < VA30 SP5 or VA40 SP2), Symbia E/S (All VB22 versions < VB22A-UD03), Symbia Evo (All VB22 versions < VB22A-UD03), Symbia Intevo (All VB22 versions < VB22A-UD03), Symbia T (All VB22 versions < VB22A-UD03), Symbia.net (All VB22 versions < VB22A-UD03), syngo.via VB10 (All versions), syngo.via VB20 (All versions), syngo.via VB30 (All versions), syngo.via VB40 (All versions < VB40B HF06), syngo.via VB50 (All versions), syngo.via VB60 (All versions < VB60B HF02). The application deserialises untrusted data without sufficient validations that could result in an arbitrary deserialization. This could allow an unauthenticated attacker to execute code in the affected system if ports 32912/tcp or 32914/tcp are reachable.

Category

9.8
CVSS
Severity: Critical
CVSS 3.1 •
CVSS 2.0 •
EPSS 1.23% Top 25%
Affected: Siemens Biograph Horizon PET/CT Systems
Affected: Siemens MAGNETOM Family
Affected: Siemens MAMMOMAT Revelation
Affected: Siemens NAEOTOM Alpha
Affected: Siemens SOMATOM X.cite
Affected: Siemens SOMATOM X.creed
Affected: Siemens SOMATOM go.All
Affected: Siemens SOMATOM go.Now
Affected: Siemens SOMATOM go.Open Pro
Affected: Siemens SOMATOM go.Sim
Affected: Siemens SOMATOM go.Top
Affected: Siemens SOMATOM go.Up
Affected: Siemens Symbia E/S
Affected: Siemens Symbia Evo
Affected: Siemens Symbia Intevo
Affected: Siemens Symbia T
Affected: Siemens Symbia.net
Affected: Siemens syngo.via VB10
Affected: Siemens syngo.via VB20
Affected: Siemens syngo.via VB30
Affected: Siemens syngo.via VB40
Affected: Siemens syngo.via VB50
Affected: Siemens syngo.via VB60
Published at:
Updated at:

References

Frequently Asked Questions

What is the severity of CVE-2022-29875?
CVE-2022-29875 has been scored as a critical severity vulnerability.
How to fix CVE-2022-29875?
To fix CVE-2022-29875, make sure you are using an up-to-date version of the affected component(s) by checking the vendor release notes. As for now, there are no other specific guidelines available.
Is CVE-2022-29875 being actively exploited in the wild?
It is possible that CVE-2022-29875 is being exploited or will be exploited in a near future based on public information. According to its EPSS score, there is a ~1% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
What software or system is affected by CVE-2022-29875?
CVE-2022-29875 affects Siemens Biograph Horizon PET/CT Systems, Siemens MAGNETOM Family, Siemens MAMMOMAT Revelation, Siemens NAEOTOM Alpha, Siemens SOMATOM X.cite, Siemens SOMATOM X.creed, Siemens SOMATOM go.All, Siemens SOMATOM go.Now, Siemens SOMATOM go.Open Pro, Siemens SOMATOM go.Sim, Siemens SOMATOM go.Top, Siemens SOMATOM go.Up, Siemens Symbia E/S, Siemens Symbia Evo, Siemens Symbia Intevo, Siemens Symbia T, Siemens Symbia.net, Siemens syngo.via VB10, Siemens syngo.via VB20, Siemens syngo.via VB30, Siemens syngo.via VB40, Siemens syngo.via VB50, Siemens syngo.via VB60.
This platform uses data from the NIST NVD, MITRE CVE, MITRE CWE, First.org and CISA KEV but is not endorsed or certified by these entities. CVE is a registred trademark of the MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. CWE is a registred trademark of the MITRE Corporation and the authoritative source of CWE content is MITRE's CWE web site.
© 2025 Under My Watch. All Rights Reserved.