Siemens Healthineers SHSA-160244 hit syngo.plaza VB30E before VB30E_HF05. CVE-2024-52335, unauthenticated SQL injection, base score 9.8. No auth, no user interaction.
SQL injection arises when an application assembles a database query by pasting user-supplied text straight into the command instead of passing it as a separate parameter. The database cannot distinguish the developer's intended query from an attacker's added clause, so input crafted to break out of the expected field is executed as instructions against the data. When the flaw needs no login, any host able to reach the interface can send that input.
SQL injection in 2024 on an imaging platform is a hard thing to read. It is the oldest bug in the web-application book, and it still puts a database of medical imaging in an attacker hands with one crafted request. Pair it with the later syngo.plaza password advisory and you have two findings in the same product line, both about the boundary between the app and its database.
An imaging platform's database is the index to studies, reports and the identifiers that link them to patients. Arbitrary queries against it mean records can be read, altered or removed, and the integrity of what a clinician later retrieves can no longer be assumed. A compromise at the data layer is quieter than a crash, and it can be harder to detect once the request has been served.
The persistence of this weakness in clinical software owes much to how long these platforms stay in service. Code authored in an earlier era survives version after version, and query-building habits that predate modern safeguards remain inside products still deployed across radiology departments. A finding in one release often points to a pattern woven through the wider codebase rather than to a single stray line.
Fixed in VB30E_HF05. Parameterize every query. There is no clever exception, no performance argument, no legacy reason good enough to concatenate user input into SQL, and there has not been for twenty years.