Application Security

Severe Denial of Service Vulnerability Identified in Orthanc DICOM Server

FORTSECURE GLOBAL· 2026-09-11🛰 CISA Cybersecurity Advisories
#Vulnerability#Healthcare#Application Security#Cyber Risk

A high-severity integer overflow in Orthanc DICOM Server could enable attackers to cause denial-of-service states across medical imaging infrastructures.

A significant security advisory highlights an integer overflow vulnerability in the Orthanc DICOM Server, an open-source medical imaging platform widely utilized in healthcare facilities. With a CVSS score of 8.1, this vulnerability allows authenticated remote threat actors to trigger an out-of-bounds heap write, leading to unexpected application termination and denial of service across clinical diagnostic pipelines.

Attack Mechanics and Healthcare Impact

The defect occurs during image decoding processes, specifically when Orthanc handles maliciously crafted PNG or JPEG image files. An attacker with upload or network-level access can supply a malicious image that induces an integer overflow, triggering a memory crash. In healthcare environments where continuous access to radiological imaging and diagnostic records is vital, crashing the imaging server disrupts clinical workflows and poses downstream patient safety risks.

Defensive Recommendations

Healthcare IT and biomedical engineering teams should implement the following protective measures:

  • Upgrade Orthanc DICOM Server instances to the latest patched software version provided by the maintainers.
  • Isolate medical imaging networks from public or untrusted enterprise networks using robust VLANs and access control lists.
  • Enforce strict authentication controls and review user permissions to ensure only authorized endpoints can transmit image files to the DICOM archive.

แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: CISA Cybersecurity Advisories

เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000

บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog