Impact
A malicious or compromised server can make a DCMTK client that uses bit‑preserving C‑GET storage mode write files outside the specified output directory, by supplying relative or absolute paths. This path traversal flaw (CWE‑22) enables an attacker to create or overwrite arbitrary files on the client’s file system.
Affected Systems
The vulnerability affects the OFFIS DICOM: DCMTK Toolkit. Version information is not specified in the report, indicating that all releases before the published fix are potentially vulnerable.
Risk and Exploitability
The CVSS score of 9.3 classifies this as high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the high CVSS combined with the capability to write arbitrary files makes it a serious risk. An attacker can trigger exploitation by issuing a C‑GET request to a vulnerable client, typically from a compromised or malicious server. The attack does not require special privileges on the client and can be performed remotely.
OpenCVE Enrichment