VDB

CVE-2022-2120

CVE-2022-2120 PUBLISHED CVSS 7.5 HIGH

OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

EPSS 3.11% · 86.8th percentile

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
3.11%
86.8th percentile

Affected Products

VendorProductVersions
OFFISDCMTKunspecified
offisdcmtk0

Timeline

  • Jun 24, 2022 CVE Published
  • Jun 25, 2022 EPSS Score
  • Jul 5, 2022 CVE Updated
  • Aug 13, 2022 EPSS Score
  • Sep 30, 2022 EPSS Score
  • Jan 3, 2023 EPSS Score
  • Feb 20, 2023 EPSS Score
  • Apr 9, 2023 EPSS Score
  • May 27, 2023 EPSS Score
  • Aug 30, 2023 EPSS Score
  • Oct 17, 2023 EPSS Score
  • Jan 21, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›