Application Security
Severe Heap Overflow Vulnerability Discovered in Orthanc DICOM Server
A high-severity integer overflow flaw in the Orthanc DICOM Server could enable remote authenticated attackers to trigger a Denial-of-Service condition.
A high-severity vulnerability has been disclosed in the widely used Orthanc DICOM Server, an open-source medical imaging system deployed across healthcare organizations globally. The issue, flagged in a medical advisory by CISA, carries a CVSS score of 8.1 and impacts the availability of vital diagnostic image storage services.
Technical Impact on Healthcare Operations
The flaw involves an integer overflow or wraparound condition during the image-decoding phase. Specifically, when an authenticated remote user submits a specially crafted PNG or JPEG image file, the Orthanc service mishandles memory calculation, resulting in an out-of-bounds heap write. This heap overflow causes the core Orthanc process to crash abruptly, resulting in a denial-of-service (DoS) state.
In healthcare environments, imaging servers are critical infrastructure. Disruptions to DICOM availability can stall clinical workflows, delay life-saving diagnoses, and disrupt surgical planning. While the exploit requires authentication, compromised clinical credentials or insider threats could trigger widespread outages across radiology pipelines.
Defensive Strategies for Medical Facilities
Healthcare cybersecurity administrators must take decisive action to protect digital imaging systems. It is recommended to update Orthanc DICOM servers to the latest patched release to resolve the image parsing flaw. Furthermore, organizations should segment DICOM servers on dedicated clinical VLANs, completely isolated from direct public internet exposure. Finally, implement robust identity controls, including strong password policies, role-based access control (RBAC), and continuous monitoring for anomalous image uploads or unexpected process restarts within medical data environments.
แหล่งที่มา: CISA Cybersecurity Advisories เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000 บทความต้นฉบับ: อ่านต้นฉบับ
Source Attribution
แหล่งที่มา: CISA Cybersecurity Advisories
เผยแพร่ครั้งแรก: Thu, 10 Sep 26 12:00:00 +0000
บทความต้นฉบับ: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-26-253-02
* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์
