Siemens Healthineers advisory SSA-016040 covers syngo.plaza VB30E before VB30E_HF07. CVE-2024-52334, weak encoding for a stored password, base score 5.3.

Reversible password storage tends to survive in long-lived clinical products because it solves an immediate engineering problem. A system that can decode its own stored secret can support legacy integrations, printed recovery steps and support staff who reset accounts by hand. Each of those conveniences quietly assumes the password store will never be read by anyone hostile, and on imaging software that assumption holds only until the moment it does not.

The record such a platform holds is not incidental. syngo.plaza sits in the imaging workflow, and an account recovered from its password store is an account inside the system that reads, routes and stores studies. Credentials pulled from a single weak store also travel, because operators reuse them across the consoles and shares that a hospital imaging estate is strung together from.

Weak encoding is not encryption. It is a reversible transform that looks like protection to an auditor and offers none to an attacker who can read the store. Recover the scheme and the passwords fall out. Store them hashed, salted, one-way, so that not even your own software can recover the plaintext. The fix is VB30E_HF07.

The advisory itself follows the shape coordinated disclosure has settled into for large device makers: a vendor security bulletin with its own identifier, a named vulnerability record, and a hotfix folded into the affected release. What the finding signals is narrower and more stubborn. Credential storage is among the most basic controls in software, and the weak form keeps producing advisories on medical platforms because it is cheap to build and, once shipped, close to permanent in the field.