CVE-2025-58406

MEDIUM

CGM CLININET - Info Disclosure

Title source: llm

Description

The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.

Scores

CVSS v3 4.3
EPSS 0.0007
EPSS Percentile 21.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Classification

CWE
CWE-693
Status published

Affected Products (1)

cgm/clininet < 2025.ms3

Timeline

Published Mar 02, 2026
Tracked Since Mar 02, 2026