VDB
CVE-2022-2120
CVE-2022-2120
PUBLISHED
CVSS 7.5 HIGH
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
EPSS 3.11% · 86.8th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.11%
86.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| OFFIS | DCMTK | unspecified |
| offis | dcmtk | 0 |
Timeline
- Jun 24, 2022 CVE Published
- Jun 25, 2022 EPSS Score
- Jul 5, 2022 CVE Updated
- Aug 13, 2022 EPSS Score
- Sep 30, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Feb 20, 2023 EPSS Score
- Apr 9, 2023 EPSS Score
- May 27, 2023 EPSS Score
- Aug 30, 2023 EPSS Score
- Oct 17, 2023 EPSS Score
- Jan 21, 2024 EPSS Score