Impact
The vulnerability is an uncontrolled mutual recursion between the parseDataSet() and parseSequence() functions in the XML‑to‑DICOM converter of DCMTK 3.7.0. Crafting an XML file with deeply nested sequence and item elements forces the parser to repeatedly call these functions until the call stack is exhausted, causing the xml2dcm tool or any service that uses it to crash. The weakness is an instance of Uncontrolled Recursion and leads to a denial of service.
Affected Systems
The affected product is OFFIS DCMTK 3.7.0, as listed in the CNA data. Any deployment that uses the xml2dcm converter or services that convert untrusted XML to DICOM with this code is affected. No other version ranges are explicitly disclosed in the data.
Risk and Exploitability
The CVSS score of 6.8 indicates a medium to high severity impact. Because no EPSS score is available, the realistic exploitation probability is unknown; however, the vulnerability can be exploited by an attacker who can supply a crafted XML document to the converter. Based on the description, the likely attack vector is an externally supplied XML file, possibly via the command line or a network service that performs XML‑to‑DICOM conversion. Since the CVE is not listed in CISA KEV, documented active exploitation is not known. The attack would require access to a service or tool that processes untrusted XML and would result in a crash and potential service downtime.
OpenCVE Enrichment