PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-54551 FUJIFILM Healthcare Americas Corporation CVE debrief

CVE-2025-54551 is a privilege escalation issue in FUJIFILM Healthcare Americas Synapse Mobility versions prior to 8.2. According to the advisory, an attacker may bypass authentication and access information beyond role-based access controls. The vendor and CISA describe upgrade and configuration-based mitigations, and patches are available for supported affected versions.

Vendor
FUJIFILM Healthcare Americas Corporation
Product
Synapse Mobility
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2025-08-21
Original CVE updated
2025-08-21
Advisory published
2025-08-21
Advisory updated
2025-08-21

Who should care

Administrators and security teams responsible for FUJIFILM Healthcare Americas Synapse Mobility deployments, especially environments that rely on the application for controlled access to protected healthcare information.

Technical summary

The advisory describes an external control of a Web parameter that can be abused to elevate privileges. The supplied CVSS vector is AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N, which aligns with a network-reachable issue requiring low privileges and no user interaction. The impact described in the advisory is authentication bypass and access to information beyond role-based access controls. Affected versions are prior to 8.2; patches are noted for versions 8.0-8.1.1, and the vendor also provides temporary mitigation steps.

Defensive priority

Medium priority: plan to upgrade to 8.2 or later as soon as practical, or apply the documented mitigations immediately if upgrade cannot happen right away.

Recommended defensive actions

  • Upgrade Synapse Mobility to version 8.2 or later.
  • If you cannot upgrade immediately, disable the search function in the configurator settings.
  • Remove access to the search function for all users by unchecking the "Allow plain text accession number" option in the admin security settings.
  • Use the SecureURL feature as the only allowed access path when applying the temporary mitigation.
  • Apply the vendor patches released for versions 8.0-8.1.1 if you are on a supported affected release.
  • If the product is past end of support, follow the vendor guidance to update to the latest available version.
  • Validate that role-based access controls are enforced after remediation.

Evidence notes

Primary evidence comes from the CISA CSAF advisory ICSMA-25-233-01 and the supplied vendor description. The source states that Synapse Mobility versions prior to 8.2 contain a privilege escalation vulnerability through external control of a Web parameter. It also states that exploitation could allow authentication bypass and access beyond role-based access controls. Mitigations listed in the source include upgrading to 8.2 or later, disabling the search function in configurator settings, unchecking "Allow plain text accession number," and using SecureURL only. The supplied enrichment marks the CVE as not in CISA KEV.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-54551 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-54551

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-54551 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-54551

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsma-25-233-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-233-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.