CVE-2025-58406
Awaiting Analysis Awaiting Analysis - Queue
Missing Security HTTP Headers in CGM CLININET Enable Client-Side Attacks

Publication date: 2026-03-02

Last updated on: 2026-03-09

Assigner: CERT.PL

Description
The CGM CLININET application respond without essential security HTTP headers, exposing users to client‑side attacks such as clickjacking, MIME sniffing, unsafe caching, weak cross‑origin isolation, and missing transport security controls.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-03-02
Last Modified
2026-03-09
Generated
2026-06-16
AI Q&A
2026-03-02
EPSS Evaluated
2026-06-15
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
cgm clininet to 2025.ms3 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-693 The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability in the CGM CLININET application arises because it responds without essential security HTTP headers. This omission exposes users to various client-side attacks.

  • Clickjacking
  • MIME sniffing
  • Unsafe caching
  • Weak cross-origin isolation
  • Missing transport security controls
Impact Analysis

This vulnerability can impact you by making your interactions with the CGM CLININET application susceptible to client-side attacks. These attacks can lead to unauthorized actions such as clickjacking, where attackers trick users into clicking hidden elements, or exploitation through MIME sniffing and unsafe caching, potentially compromising data integrity and confidentiality.

Compliance Impact

I don't know

Detection Guidance

I don't know

Mitigation Strategies

I don't know

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-58406. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart