CVE-2025-35032
BaseFortify
Publication date: 2025-09-29
Last updated on: 2025-10-02
Assigner: Cybersecurity and Infrastructure Security Agency (CISA) U.S. Civilian Government
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| medical_informatics_engineering | enterprise_health | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-434 | The product allows the upload or transfer of dangerous file types that are automatically processed within its environment. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability in Medical Informatics Engineering Enterprise Health allows authenticated users to upload arbitrary files. The risk depends on how these uploaded files are accessed or handled by the system. It was fixed as of April 8, 2025.
How can this vulnerability impact me? :
The impact depends on how the uploaded arbitrary files are accessed. Potentially, it could lead to limited integrity issues since the CVSS indicates low integrity impact, but no confidentiality or availability impact. The exact consequences depend on the system's handling of these files.
What immediate steps should I take to mitigate this vulnerability?
Apply the fix released as of 2025-04-08 to Medical Informatics Engineering Enterprise Health to prevent authenticated users from uploading arbitrary files.