top of page
perceptive_background_267k.jpg

A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This impacts the function executeOnReception/executeOnEndOfStudy of the file dcmnet/apps/storesc…

Published:

5 April 2026 at 22:00:00

Alert date:

6 April 2026 at 16:03:20

Source:

nvd.nist.gov

Click to open the original link from this advisory

Critical Infrastructure, Enterprise Applications

A critical security vulnerability has been discovered in OFFIS DCMTK up to version 3.7.0. The flaw affects the executeOnReception and executeOnEndOfStudy functions in the storescp component, specifically in the dcmnet/apps/storescp.cc file. Exploitation of this vulnerability can lead to OS command injection attacks. The vulnerability can be exploited remotely, making it particularly dangerous. A patch has been released with the identifier edbb085e45788dccaf0e64d71534cfca925784b8. Organizations using affected versions of DCMTK should immediately apply the available patch to mitigate this security risk.

Technical details

Mitigation steps:

Affected products:

OFFIS DCMTK

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page