ENAD CADx 취약점ENAD CADx vulnerabilities
AINEX는 의료기기 사이버보안 규제(EU MDR, MDCG 2019-16)에 따라 제품에서 확인된 취약점을 본 채널로 공개합니다. 아래 내용은 인증이나 로그인 없이 열람할 수 있습니다.In line with medical device cybersecurity regulations (EU MDR, MDCG 2019-16), AINEX discloses vulnerabilities identified in its products through this channel. The information below can be read without authentication.
요약Summary
ENAD CADx 에 포함된 서드파티 소프트웨어 구성요소에 대해 공개된 취약점(CVE)을 공지합니다.This bulletin discloses the vulnerabilities (CVEs) published against the third-party software components included in ENAD CADx.
ENAD CADx 는 내시경 검사 중 획득한 영상을 실시간으로 분석해 의료진의 진단 판단을 보조하는 소프트웨어 의료기기입니다. 장비는 내시경 장치로부터 영상을 직접 입력받는 전용 어플라이언스로 운영됩니다.ENAD CADx is a software medical device that analyzes images acquired during endoscopy in real time to support the clinician's diagnostic assessment. It operates as a dedicated appliance that receives video directly from the endoscopy device.
영향 제품Products impacted
- ENAD CADx, 소프트웨어 버전software version 1.1.0.0 (EU)
구성요소 취약점Component vulnerabilities
제품에 포함된 서드파티 구성요소에 대해 공개된 CVE 입니다. 전체 구성요소 목록은CVEs published against the third-party components included in the product. The full component inventory is on the SBOM 페이지SBOM page에서 확인할 수 있습니다..
| 구성요소Component | 버전Version | CVE |
|---|---|---|
| Ubuntu | 24.04.4 LTS24.04.4 LTS | CVE-2025-32463CVE-2024-6387CVE-2025-26466CVE-2025-5054 |
| NVIDIA CUDA Toolkit | 12.8.112.8.1 | CVE-2025-23247CVE-2025-23275CVE-2025-23308CVE-2025-23339CVE-2025-33228CVE-2025-33229CVE-2025-33230CVE-2025-23273CVE-2025-23338CVE-2025-33231CVE-2025-23248CVE-2025-23255CVE-2025-23271CVE-2025-23340CVE-2025-23346 |
| OpenSSL | 3.0.133.0.13 | CVE-2025-15467CVE-2025-69419CVE-2025-69420CVE-2025-69421CVE-2026-22795CVE-2026-22796CVE-2025-68160CVE-2025-69418 |
| Ffmpeg | 7.1.17.1.1 | CVE-2023-51791CVE-2023-51793CVE-2023-51795CVE-2023-51798CVE-2023-51794CVE-2025-22921CVE-2023-51797CVE-2025-25468CVE-2025-25469CVE-2025-10256CVE-2025-12343CVE-2023-51796 |
| OpenCV | 4.11.04.11.0 | CVE-2025-53644 |
| OpenCV-contrib | 4.11.04.11.0 | CVE-2025-53644 |
| Qt Framework | 6.8.26.8.2 | CVE-2025-5683 |
AINEX 권장 조치Recommended actions from AINEX
- 의료기관은 AINEX 또는 공인 서비스 담당자가 안내하는 절차에 따라 소프트웨어를 최신 버전으로 유지하십시오.Healthcare institutions should keep the software up to date, following the procedure provided by AINEX or an authorized service representative.
- 장비는 시술 구역 내 통제된 장소에 두고, 인가된 인원만 물리적으로 접근할 수 있도록 관리하십시오.Keep the device in a controlled location within the procedure area, with physical access restricted to authorized personnel.
- 소프트웨어 갱신과 서비스는 AINEX 또는 공인 서비스 담당자를 통해서만 수행하십시오.Have software updates and servicing performed only by AINEX or an authorized service representative.
문의For more information
추가 정보가 필요한 고객은 contact@ainex.io 로 문의해 주십시오. AINEX 제품에서 보안 취약점을 발견하신 경우에도 동일한 주소로 신고해 주십시오.Customers needing additional information should write to contact@ainex.io. If you discover a security vulnerability in an AINEX product, report it to the same address.