CVE-2025-58406
Awaiting Analysis
Awaiting Analysis - Queue
Missing Security HTTP Headers in CGM CLININET Enable Client-Side Attacks
Publication date: 2026-03-02
Last updated on: 2026-03-09
Assigner: CERT.PL
Description
Description
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| cgm | clininet | to 2025.ms3 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-693 | The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. |