DNA View

CVE-2025-1002

Medium
Low Medium High Critical
5.7
CVSS Score
Published: Feb 10, 2025
Last Modified: Mar 03, 2025

Vulnerability Description

MicroDicom DICOM Viewer version 2024.03

fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.

CVSS Metrics

Common Vulnerability Scoring System

Vector String:

CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Vector
A
Attack Complexity
L
Privileges Required
N
User Interaction
R
Scope
U
Confidentiality
N
Integrity
H
Availability
N

Known Affected Software

1 configuration(s) from 1 vendor(s)

dicom_viewer
Version:
2024.3
CPE:
cpe:2.3:a:microdicom:dicom_viewer:2024.3:*:*:*:*:*:*:*
This vulnerability affects 1 software configuration(s). Ensure you patch all affected systems.

Severity Details

5.7
out of 10.0
Medium

Weakness Type (CWE)

CWE-295 Top 25 #23

Improper Certificate Validation

Description
The product does not validate, or incorrectly validates, a certificate.
Typical Severity
High
OWASP Top 10
A02:2021-Cryptographic Failures
Abstraction Level
Base

Key Information

Published Date
February 10, 2025

Related News Articles

Latest news and updates about CVE-2025-1002