DCMTK Vulnerabilities Expose Medical Imaging Systems to File Write and DoS
ID: 23afb171-7d23-5117-b2a6-c44b8251a0e9
STIX ID: report--23afb171-7d23-5117-b2a6-c44b8251a0e9
Feed Name: securityonline.info
CISA published an advisory for five vulnerabilities in the OFFIS DCMTK DICOM toolkit (affecting versions ≤ 3.7.0), the most severe being a CVSS 9.8 path-traversal/file-write (CVE-2026-50003) that lets a malicious or compromised DICOM server cause clients to write files outside their output directories; additional issues include unauthenticated data exposure and memory-leak/crash conditions. The maintainer has released fixes; mitigations include network segmentation, keeping DICOM services off the public internet, and running services with least privilege; no confirmed active exploitation has been reported.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
