Sante DICOM Viewer Pro DCM File Parsing Use-After-Free Information Disclosure Vulnerability
CVE-2023-32135

6.5MEDIUM

Key Information:

Vendor

Sante

Vendor
CVE Published:
3 May 2024

What is CVE-2023-32135?

A vulnerability exists in Sante DICOM Viewer Pro that arises during the processing of DCM files. The flaw is due to improper validation of object existence prior to executing operations on it, allowing remote attackers to potentially disclose sensitive information. To exploit this vulnerability, user interaction is necessary; users must either visit a malicious website or open a compromised DCM file. Attackers can take advantage of this issue in conjunction with other vulnerabilities to attempt arbitrary code execution within the context of the application, posing risks to user data integrity and confidentiality.

Affected Version(s)

DICOM Viewer Pro 12.1.5.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.