CVE-2024-37999
A vulnerability has been identified in Medicalis Workflow Orchestrator (All versions). The affected application executes as a trusted account with high privileges and network access. This could allow an authenticated local attacker to escalate privileges.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.5
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.14%
- CWE
- CWE-282
- Published
- 2024-07-08
- Last modified
- 2026-03-13
Affected products
- Siemens Medicalis Workflow Orchestrator
Weakness type
Related vulnerabilities
- CVE-2026-86769 — Snipe-IT before 8.7.0 Audit Log Misattribution via Consumables Checkout
- CVE-2026-50130 — Pi-hole: Local privilege escalation from `pihole` user to root via `/etc/pihole/logrotate`
- CVE-2026-40214 — In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project...
- CVE-2026-3867 — An improper ownership management vulnerability has been identified in Moxa’s Secure Router. Because...
- CVE-2026-23514 — Kiteworks Core before 9.2.2 is vulnerable to Improper Ownership Management
- CVE-2025-57732 — In JetBrains TeamCity before 2025.07.1 privilege escalation was possible due to incorrect directory...
- CVE-2025-1112 — IBM OpenPages with Watson information disclosure
- CVE-2025-46416 — The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can...