CVE-2025-1002
MediumVulnerability Description
MicroDicom DICOM Viewer version 2024.03
fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.
CVSS Metrics
Common Vulnerability Scoring System
Vector String:
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Known Affected Software
1 configuration(s) from 1 vendor(s)
cpe:2.3:a:microdicom:dicom_viewer:2024.3:*:*:*:*:*:*:*
Severity Details
Weakness Type (CWE)
Improper Certificate Validation
- Description
- The product does not validate, or incorrectly validates, a certificate.
- Typical Severity
- High
- OWASP Top 10
- A02:2021-Cryptographic Failures
- Abstraction Level
- Base
Key Information
- Published Date
- February 10, 2025
External Resources
Related News Articles
Latest news and updates about CVE-2025-1002
