CVE-2025-10350

HIGH

CGM NETRAAD < 7.9.0 - SQL Injection via Imageserver C-FIND Query Processing

Title source: llm
STIX 2.1

Description

SQL Injection vulnerability in "imageserver" module when processing C-FIND queries in CGM NETRAAD software allows attacker connected to PACS gaining access to database, including data processed by GCM CLININET software.This issue affects CGM NETRAAD with imageserver module in versions before 7.9.0.

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/en/posts/2026/03/CVE-2025-10350/

Scores

CVSS v4 8.8
EPSS 0.0019
EPSS Percentile 8.3%
CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Published Mar 02, 2026
Tracked Since Mar 02, 2026