OFFIS DCMTK Toolkit

Plan PatchCVSS 9.8ICS-CERT ICSMA-26-181-01Jun 30, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Multiple vulnerabilities in DCMTK (DICOM Toolkit) versions 3.7.0 and earlier allow remote attackers to write files via path traversal (CWE-22), access unauthorized information due to improper resource cleanup (CWE-401), and cause denial of service through type confusion vulnerabilities (CWE-843). These vulnerabilities affect DCMTK client and server processes that handle medical imaging data exchange.

What this means
What could happen
An attacker could write files to the system, access sensitive DICOM medical image data, exhaust memory, or crash DCMTK server processes that manage medical imaging workflows. This could disrupt patient image handling or allow unauthorized access to protected health information.
Who's at risk
This affects any organization using DCMTK (DICOM Toolkit) for medical imaging applications, including hospitals, clinics, radiology departments, and Picture Archiving and Communication System (PACS) operators that rely on DCMTK for image transfer, storage, or processing.
How it could be exploited
An attacker with network access to a DCMTK client or server process (typically port 104 for DICOM) can send malformed DICOM requests that trigger path traversal (CWE-22), resource exhaustion, or type confusion vulnerabilities. The attacker requires no authentication or user interaction.
Prerequisites
  • Network access to DCMTK client or server process (typically DICOM port 104)
  • DCMTK version 3.7.0 or earlier
remotely exploitableno authentication requiredlow complexityhigh CVSS score (9.8)affects medical data confidentiality and availability
Exploitability
Unlikely to be exploited — EPSS score 0.7%
Affected products (1)
ProductAffected VersionsFix Status
DCMTK≤ 3.7.0Fix available
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, restrict network access to DCMTK processes to trusted hosts only using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate DCMTK to the latest version available from https://github.com/DCMTK/dcmtk/releases
Long-term hardening
0/1
HARDENINGReview firewall rules and network segmentation to ensure DICOM servers are not directly accessible from untrusted networks
API: /api/v1/advisories/05f08c9f-7e02-4ca1-b438-24c1a16f75a8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

OFFIS DCMTK Toolkit | CVSS 9.8 - OTPulse