VDB
CVE-2022-2119
CVE-2022-2119
PUBLISHED
CVSS 7.5 HIGH
OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
EPSS 5.68% · 90.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
5.68%
90.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| offis | dcmtk | 0 |
| OFFIS | DCMTK | unspecified |
Exploit Intelligence
Timeline
- Jun 24, 2022 CVE Published
- Jun 25, 2022 EPSS Score
- Jul 5, 2022 CVE Updated
- Aug 13, 2022 EPSS Score
- Sep 29, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Feb 20, 2023 EPSS Score
- Apr 8, 2023 EPSS Score
- May 26, 2023 EPSS Score
- Aug 30, 2023 EPSS Score
- Oct 16, 2023 EPSS Score
- Jan 20, 2024 EPSS Score