U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2022-29875

Change History

Initial Analysis by NIST 6/10/2022 8:45:14 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:biograph_horizon_pet\/ct_systems_firmware:*:*:*:*:*:*:*:* versions from (including) vj30 up to (excluding) vj30c-ud01
     OR
          cpe:2.3:h:siemens:biograph_horizon_pet\/ct_systems:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va10b:*:*:*:*:*:*:*
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va12m:*:*:*:*:*:*:*
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va12s:*:*:*:*:*:*:*
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va20a:*:*:*:*:*:*:*
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va30a:*:*:*:*:*:*:*
          *cpe:2.3:o:siemens:magnetom_numaris_x_firmware:va31a:*:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:magnetom_numaris_x:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:mammomat_revelation_firmware:*:*:*:*:*:*:*:* versions from (including) vc20 up to (excluding) vc20d
     OR
          cpe:2.3:h:siemens:mammomat_revelation:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:naeotom_alpha_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:naeotom_alpha:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_go.all_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_go.all_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_go.all_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_go.all:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_go.now_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_go.now_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_go.now_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_go.now:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_go.open_pro_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_go.open_pro_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_go.open_pro_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_go.open_pro:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_go.sim_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_go.sim_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_go.sim_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_go.sim:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_go.up_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_go.up_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_go.up_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_go.up:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_x.cite_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_x.cite_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_x.cite_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_x.cite:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:somatom_x.creed_firmware:*:*:*:*:*:*:*:* versions up to (excluding) va30
          *cpe:2.3:o:siemens:somatom_x.creed_firmware:va30:-:*:*:*:*:*:*
          *cpe:2.3:o:siemens:somatom_x.creed_firmware:va40:-:*:*:*:*:*:*
     OR
          cpe:2.3:h:siemens:somatom_x.creed:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:symbia_e_firmware:*:*:*:*:*:*:*:* versions from (including) vb22 up to (excluding) vb22a-ud03
     OR
          cpe:2.3:h:siemens:symbia_e:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:symbia_evo_firmware:*:*:*:*:*:*:*:* versions from (including) vb22 up to (excluding) vb22a-ud03
     OR
          cpe:2.3:h:siemens:symbia_evo:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:symbia_intevo_firmware:*:*:*:*:*:*:*:* versions from (including) vb22 up to (excluding) vb22a-ud03
     OR
          cpe:2.3:h:siemens:symbia_intevo:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:symbia_s_firmware:*:*:*:*:*:*:*:* versions from (including) vb22 up to (excluding) vb22a-ud03
     OR
          cpe:2.3:h:siemens:symbia_s:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
AND
     OR
          *cpe:2.3:o:siemens:symbia_t_firmware:*:*:*:*:*:*:*:* versions from (including) vb22 up to (excluding) vb22a-ud03
     OR
          cpe:2.3:h:siemens:symbia_t:-:*:*:*:*:*:*:*
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:siemens:symbia.net:*:*:*:*:*:*:*:* versions from (including) vb22 up to (including) vb22a-ud03
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:a:siemens:syngo.via:vb10:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:syngo.via:vb20:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:syngo.via:vb30:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:syngo.via:*:*:*:*:*:*:*:* versions from (including) vb40 up to (excluding) vb40b
     *cpe:2.3:a:siemens:syngo.via:vb40b:-:*:*:*:*:*:*
     *cpe:2.3:a:siemens:syngo.via:vb50:*:*:*:*:*:*:*
     *cpe:2.3:a:siemens:syngo.via:*:*:*:*:*:*:*:* versions from (including) vb60 up to (excluding) vb60b
     *cpe:2.3:a:siemens:syngo.via:vb60b:-:*:*:*:*:*:*
Added CVSS V2

								
							
							
						
NIST (AV:N/AC:M/Au:N/C:C/I:C/A:C)
Added CVSS V3.1

								
							
							
						
NIST AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
NIST CWE-502
Changed Reference Type
https://www.siemens-healthineers.com/support-documentation/cybersecurity/shsa-455016 No Types Assigned
https://www.siemens-healthineers.com/support-documentation/cybersecurity/shsa-455016 Mitigation, Vendor Advisory