The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the privileges of the targeted user.
Metrics
Affected Vendors & Products
References
History
Mon, 02 Mar 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 02 Mar 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The vulnerability enables an attacker to fully bypass authentication in CGM CLININET and gain access to any active user account by supplying only the username, without requiring a password or any other credentials. Obtaining a session ID is sufficient for session takeover and grants access to the system with the privileges of the targeted user. | |
| Title | Lack of API authentication allowing session generation for any user | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: CERT-PL
Published:
Updated: 2026-03-02T13:22:33.554Z
Reserved: 2025-03-14T14:54:23.998Z
Link: CVE-2025-30035
Updated: 2026-03-02T13:22:28.229Z
Status : Received
Published: 2026-03-02T12:16:00.920
Modified: 2026-03-02T12:16:00.920
Link: CVE-2025-30035
No data.
OpenCVE Enrichment
No data.