CVE-2025-48981
8.6CompuGroup Medical · CGM MEDICO
The DNET protocol in CGM MEDICO contains an insecure implementation where encryption is optional, allowing attackers on the intranet to intercept and manipulate sensitive data.
Executive summary
An insecure implementation of the DNET protocol in CGM MEDICO exposes internal communications to interception and manipulation, presenting a high risk to data confidentiality and integrity.
Vulnerability
This vulnerability involves the use of an unencrypted proprietary network protocol (DNET) that fails to mandate secure communication, allowing an unauthenticated attacker positioned within the local network to perform man-in-the-middle attacks.
Business impact
Successful exploitation allows unauthorized actors to eavesdrop on sensitive medical data or inject malicious commands into the system. Given the CVSS score of 8.6, this flaw poses a significant risk to organizational data privacy and operational safety, potentially leading to unauthorized system access or the compromise of protected health information.
Remediation
Immediate Action: Organizations should review the vendor advisory at the provided reference link and update to version 29.1 or later immediately.
Proactive Monitoring: Security teams should monitor internal network traffic for anomalous DNET protocol activity or unauthorized connection attempts within the intranet segment.
Compensating Controls: Deploy network segmentation to restrict access to the CGM MEDICO infrastructure and implement internal traffic inspection to detect unencrypted communication patterns.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
This vulnerability is classified as high severity due to the potential for unauthenticated data manipulation within a clinical environment. IT administrators must prioritize the application of vendor-provided security updates to enforce encryption for the DNET protocol, thereby closing the window of opportunity for local network-based attackers.