Description

Siemens Healthineers has issued a critical security update to address an unauthenticated SQL injection vulnerability in its syngo.plaza VB30E medical imaging software. This vulnerability, identified as CVE-2024-52335 with a CVSS score of 9.8, could potentially allow an attacker to execute malicious SQL commands and gain control of the entire database. The advisory highlights that syngo.plaza VB30E is vulnerable to SQL injection due to improper input sanitization before data is sent to the SQL server. As a result, an attacker could exploit this flaw to execute malicious SQL commands, compromising the entire database. Syngo.plaza is a widely-used Picture Archiving and Communication System (PACS) that offers healthcare professionals a comprehensive suite of tools for managing digital medical images. It allows physicians to display, process, read, report, print, communicate, distribute, store, and archive a wide range of medical imaging data, including critical images like mammograms. Given its role in healthcare, this vulnerability presents a significant security risk, as any successful exploitation could potentially undermine the integrity of sensitive patient data stored in the system.