Impact
The vulnerability is caused by uncontrolled recursion in the DcmSequenceOfItems::read() and DcmItem::read() functions of the dcmdata library, which allows a crafted DICOM dataset with deeply nested sequences to exhaust the application stack and trigger a crash. Attackers can create such a dataset and send it via a C-STORE request or process it locally with tools like dcmdump, leading to a denial of service for the affected service or utility. The flaw constitutes a CWE-674: Uncontrolled Recursion, and it requires no authentication to trigger.
Affected Systems
The flaw affects OFFIS DCMTK version 3.7.0 and earlier releases that include the unpatched dcmdata library. It is exploitable through any DICOM service built on DCMTK, including storescp, dcmrecv, and dcmqrscp, as well as local tools such as dcmdump that parse the dataset before authentication. The products impacted are the DCMTK library and DICOM services derived from it.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, and although EPSS is not available, the potential for a remote denial of service makes this a valuable target for attackers. The attack vector is a remote, unauthenticated DICOM client that sends a deeply nested dataset, causing stack exhaustion before authentication occurs. This vulnerability is not listed in CISA KEV and no public exploit is known, but because it can bring services offline it is urgent to apply the available fix or mitigation soon.
OpenCVE Enrichment