CVE-2025-30042: Cgm Clininet
High severity, CVSS 7.8. EPSS: 0.1% chance of exploitation in the next 30 days.
The CGM CLININET system provides smart card authentication; however, authentication is conducted locally on the client device, and, in reality, only the certificate number is used for access verification. As a result, possession of the certificate number alone is sufficient for authentication, regardless of the actual presence of the smart card or ownership of the private key.
Affected products
- Cgm Clininet: before 2025.ms2 (fixed in 2025.ms2)
Published 2026-03-02. Last modified 2026-06-17.