Skip to main content
Advisories

Siemens Healthineers syngo.plaza – insecure password encryption vulnerability

By 25. February 2026February 26th, 2026No Comments

During a security assessment, we discovered an insecure password encryption vulnerability (CVE-2024-52334) in Siemens Healthineers syngo.plaza VB30E, a medical imaging archiving system deployed in hospitals. The vulnerability allows an attacker to recover original passwords from insufficiently encrypted storage with a static key, potentially gaining unauthorized access to medical records.  

Discovered Vulnerability

CVSS v4.0 Score

Product:

syngo.plaza VB30E

Affected Version:

all versions < VB30E_HF07

CVE / Vendor ID:

CVE-2024-52334

Found by:

Felix Eberstaller & Bernhard Lorenz, Limes Security GmbH
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

The Finding: Weak Password Encryption in syngo.plaza

The vulnerability is classified as CWE-261 (Weak Encoding for Password). syngo.plaza did not properly encrypt stored passwords, allowing an attacker with access to the relevant data to recover plaintext credentials. 

We reported the vulnerability through coordinated disclosure, and Siemens Healthineers addressed it with a hotfix. 

Siemens Healthineers Security Advisory: SSA-016040 

Disclosure Timeline

2024:

  • Vulnerability discovered during customer engagement
  • Reported to Siemens Healthineers

10.02.2026:

  • Siemens Healthineers publishes advisory SSA-016040

We thank Siemens Healthineers for their professional handling of this disclosure.

A Pattern, Not an Anomaly

This finding did not surprise us. Static passwords, hardcoded keys, and inadequate cryptographic protections have been a persistent issue across OT products for well over two decades. The problem is not limited to any single vendor or sector, it is an industry-wide pattern rooted in historical design decisions and the unique constraints of these environments.

Our recommendation

Operators of affected systems should definitely apply the hotfix for syngo.plaza (VB30E_HF07) in accordance with recommendation SSA-016040 from Siemens Healthineers. In addition, we recommend performing regular penetration tests.

Manufacturers should remove hardcoded access data and integrate product security holistically throughout the entire lifecycle in accordance with regulatory requirements.

Your security is our mission. Let’s defend what matters!