[Japanese]

JVNDB-2025-011884

FUJIFILM Healthcare Americas Synapse Mobility vulnerable to Privilege Escalation

Overview

Synapse Mobility provided by FUJIFILM Healthcare Americas Corporation is vulnerable to privilege escalation.

* Privilege escalation vulnerability through external control of Web parameter (CWE-472) - CVE-2025-54551

Christopher Alejandro (Moroco) reported this vulnerability to CISA ICS.
JPCERT/CC, upon request from CISA ICS, coordinated with the developer.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 4.3 (Medium) [Other]
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: Low
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


FUJIFILM Healthcare Americas Corporation
  • Synapse Mobility version 8.0
  • Synapse Mobility version 8.0.1
  • Synapse Mobility version 8.0.2
  • Synapse Mobility version 8.1
  • Synapse Mobility version 8.1.1

Synapse Mobility versions 8.2x and 9.0 are not affected by this vulnerability.
Impact

By altering the parameters of the search function, a user of the product may escalate the privilege and access data that the user do not have permission to view.
Solution

[Update the Software]
Update the software to the following versions which are not affected by this vulnerability according to the information provided by the developer.

* Synapse Mobility version 9.0 or 8.2x

[Apply the patches]
The developer has provided the patches for the following versions to address this vulnerability.

* For Synapse Mobility versions 8.0 to 8.1.1

As for the details, refer to the information provided by the developer.
Vendor Information

FUJIFILM Healthcare Americas Corporation
CWE (What is CWE?)

  1. External Control of Assumed-Immutable Web Parameter(CWE-472) [Other]
CVE (What is CVE?)

  1. CVE-2025-54551
References

  1. JVN : JVNVU#94286093
Revision History

  • [2025/08/21]
      Web page was published