CVE-2024-37999: Siemens Medicalis Workflow Orchestrator

High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.

A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.

Affected products

  • Siemens Medicalis Workflow Orchestrator: any version

Published 2024-07-08. Last modified 2026-06-17.