Impact
The vulnerability is a type‑confusion flaw that allows an unauthenticated attacker to send a single crafted query to the worklist server, causing it to crash. This crash results in a loss of service availability for the affected system. The flaw does not directly compromise confidentiality or integrity but the resulting denial of service can be disruptive to medical and clinical operations.
Affected Systems
Vulnerable product: OFFIS DICOM:DCMTK Toolkit. Specific versions are not disclosed, so any build of the toolkit that includes the worklist server component may be at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates a high‑severity denial‑of‑service vulnerability. The EPSS score is not available and the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is network‑based: an unauthenticated attacker can trigger the crash by connecting to the worklist server and sending the crafted query. No special privileges or additional conditions are required beyond the presence of a valid Called AE Title, a storage directory, a lockfile, and at least one matching worklist record.
OpenCVE Enrichment