CVE-2025-30042

The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, regardless of the actual presence of the smart card or ownership of the private key.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cgm:clininet:*:*:*:*:*:*:*:*

History

17 Jun 2026, 09:08

Type Values Removed Values Added
Summary
  • (es) El sistema CGM CLININET proporciona autenticación con tarjeta inteligente; sin embargo, la autenticación se realiza localmente en el dispositivo cliente y, en realidad, solo el número de certificado se utiliza para la verificación de acceso. Como resultado, la posesión del número de certificado por sí sola es suficiente para la autenticación, independientemente de la presencia real de la tarjeta inteligente o de la posesión de la clave privada.

09 Mar 2026, 16:49

Type Values Removed Values Added
First Time Cgm clininet
Cgm
References () https://cert.pl/en/posts/2026/03/CVE-2025-10350/ - () https://cert.pl/en/posts/2026/03/CVE-2025-10350/ - Third Party Advisory
References () https://www.cgm.com/pol_pl/products/szpital/cgm-clininet.html - () https://www.cgm.com/pol_pl/products/szpital/cgm-clininet.html - Product
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:cgm:clininet:*:*:*:*:*:*:*:*

02 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-02 12:16

Updated : 2026-06-17 09:08


NVD link : CVE-2025-30042

Mitre link : CVE-2025-30042

CVE.ORG link : CVE-2025-30042


JSON object : View

Products Affected

cgm

  • clininet
CWE
CWE-603

Use of Client-Side Authentication