Orthanc DICOM Server
Plan PatchCVSS 8.1ICS-CERT ICSMA-26-253-02Sep 10, 2026
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
A heap buffer overflow vulnerability in Orthanc DICOM Server versions before 1.13.0 allows authenticated remote attackers to crash the server by uploading malicious PNG or JPEG images. The vulnerability occurs during image decoding when Orthanc writes past the end of a heap allocation. Successful exploitation results in denial of service (Orthanc process crash) with high impact on integrity and availability.
What this means
What could happen
An authenticated attacker could upload a malicious PNG or JPEG image that crashes the Orthanc DICOM server, taking down medical imaging services and preventing access to patient images.
Who's at risk
Healthcare facilities running Orthanc DICOM servers for medical imaging storage and retrieval. This includes hospitals, diagnostic imaging centers, and any organization using Orthanc to manage patient CT, MRI, X-ray, or other DICOM images.
How it could be exploited
An attacker with valid Orthanc credentials uploads a specially crafted PNG or JPEG file to the server. During image decoding, the malformed file triggers a heap buffer overflow that crashes the Orthanc process, causing denial of service.
Prerequisites
- Valid Orthanc user credentials (authentication required)
- Network access to Orthanc web interface or DICOM upload endpoint
- Ability to upload image files to the server
requires valid credentials to exploitlow attack complexityhigh impact on service availabilityaffects healthcare imaging operations
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (1)
ProductAffected VersionsFix Status
DICOM Server<1.13.0.No fix yet
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Orthanc DICOM Server to version 1.13.0 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/e41b6507-cace-4bc5-9bdf-61b3adfeddebGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.