Impact
An attacker without authentication can repeatedly send a crafted connection request to the DCMTK storescp service, causing it to leak heap memory. The memory usage grows until the service exhausts available memory and is killed, after which it stops accepting new connections until an operator restarts it. This results in a denial‑of‑service condition that impacts the availability of the DICOM service.
Affected Systems
The vulnerability affects the OFFIS DICOM DCMTK Toolkit, specifically the storescp component when running in its default single‑process mode. Any release prior to the latest GitHub release contains the flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote and unauthenticated, requiring only repeated network requests. Once exploited, the service terminates, causing a denial of service until the operator restarts it. A fix is available in the latest GitHub release; applying this update mitigates the issue.
OpenCVE Enrichment