VDB

CVE-2022-2119

CVE-2022-2119 PUBLISHED CVSS 7.5 HIGH

OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

EPSS 5.68% · 90.6th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
5.68%
90.6th percentile

Affected Products

VendorProductVersions
offisdcmtk0
OFFISDCMTKunspecified

Timeline

  • Jun 24, 2022 CVE Published
  • Jun 25, 2022 EPSS Score
  • Jul 5, 2022 CVE Updated
  • Aug 13, 2022 EPSS Score
  • Sep 29, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Feb 20, 2023 EPSS Score
  • Apr 8, 2023 EPSS Score
  • May 26, 2023 EPSS Score
  • Aug 30, 2023 EPSS Score
  • Oct 16, 2023 EPSS Score
  • Jan 20, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›