CGM maintains a focused healthcare information system product, Clininet, with a durable vulnerability signal centered on access-control and authentication weaknesses including authorization bypass through user-controlled keys, improper UI-layer restrictions, protection mechanism failures, and client-side authentication flaws. These issues reflect the sensitivity of patient-data access and the risks inherent in web-based healthcare applications where proper access controls are critical. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cgm over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-30042HIGH The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used | Mar 2, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-58402HIGH The CGM CLININET application uses direct, sequential object identifiers "MessageID" without proper authorization checks. By modifying the parameter in the GET request, an attacker | Mar 2, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-58405MEDIUM The CGM CLININET application does not implement any mechanisms that prevent clickjacking attacks, neither HTTP security headers nor HTML-based frame‑busting protections were detect | Mar 2, 2026 | 6.1 | 22 | NO | NO |
CVE-2025-58406MEDIUM The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑ | Mar 2, 2026 | 4.3 | 19 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cgm.
Media articles that mention a CVE ID that affects a product developed by Cgm — matched by CVE ID, not by vendor name.