VulnerabilityAnalyzed
CVE-2025-35032
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files.
MEDIUM 6.2EPSS 0.25%
Does this matter?
Lower severity and a low EPSS score (0.25%). Track it; it rarely justifies an emergency change on its own.
Description
Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The impact of this behavior depends on how files are accessed. This issue is fixed as of 2025-04-08.
- CVSS 4.0
- 6.2 MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:N/VI:L/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.25% probability · 17th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-434
- Affected
- mieweb/enterprise health
- Source
- 9119a7d8-5eab-497f-8521-727c672e3725
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-25-272-01.jsonThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-35032Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.