Medixant RadiAnt DICOM
MonitorCVSS 4.3ICS-CERT ICSMA-26-218-01Aug 6, 2026
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
RadiAnt DICOM versions 2025.2 and earlier contain a memory access error (CWE-787) that can cause application denial of service. When a user opens a specially crafted DICOM file, the vulnerability is triggered and the application crashes. The application includes exploit mitigations (CFG, DEP, ASLR) that limit practical exploitability.
What this means
What could happen
A maliciously crafted DICOM file could crash RadiAnt DICOM, interrupting medical image review workflows and potentially delaying diagnostic operations.
Who's at risk
Healthcare facilities and diagnostic imaging departments using RadiAnt DICOM for medical image viewing and analysis. This includes radiologists, cardiologists, and other physicians who rely on DICOM viewers for patient care decisions.
How it could be exploited
An attacker sends or tricks a user into opening a malicious DICOM file in RadiAnt DICOM. The file triggers a memory access error that crashes the application. The attacker relies on social engineering since the user must open the file.
Prerequisites
- RadiAnt DICOM version 2025.2 or earlier installed
- User must open a maliciously crafted DICOM file
- DICOM file must be delivered to or accessible by the user
remotely exploitablelow complexityrequires user interaction
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
RadiAnt DICOM≤ 2025.2No fix yet
Remediation & Mitigation
0/2
Do now
0/1HARDENINGConfigure user workflow to only open DICOM files from trusted clinical imaging systems and verified sources
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate RadiAnt DICOM to version 2026.1 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/8cdb438d-ff41-4d9c-8e02-0c373f4fe8baGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.