CVE-2025-30064

HIGH

CGM CLININET <= 2025.MS2 - Session Generation via Insufficient JWT Verification

Title source: llm
STIX 2.1

Description

An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not verify which signing algorithm was used. As a result, an attacker can use the "ex:action" parameter in the VerifyUserByThrustedService function to generate a session for any user.

Scores

CVSS v4 8.8
EPSS 0.0001
EPSS Percentile 0.9%
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-347 CWE-912
Status published
Products (1)
CGM/CGM CLININET < 2025.MS2
Published Aug 27, 2025
Tracked Since Feb 18, 2026