PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-25578 MicroDicom CVE debrief

A memory corruption vulnerability exists in MicroDicom DICOM Viewer versions 2023.3 (Build 9342) and prior due to improper validation of user-supplied data. The vulnerability, published by CISA on February 29, 2024, carries a CVSS 3.1 score of 7.8 (HIGH severity). The attack vector is local, requiring user interaction but no privileges, and can result in high impacts to confidentiality, integrity, and availability. MicroDicom has released version 2024.1 to address this issue.

Vendor
MicroDicom
Product
DICOM Viewer
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-02-29
Original CVE updated
2024-02-29
Advisory published
2024-02-29
Advisory updated
2024-02-29

Who should care

Healthcare organizations, medical imaging departments, radiology practices, and any clinical environments using MicroDicom DICOM Viewer for medical image review. Security teams responsible for medical device cybersecurity and HIPAA-covered entities maintaining secure configurations for diagnostic imaging workstations.

Technical summary

The vulnerability stems from insufficient validation of user-supplied data in MicroDicom DICOM Viewer, a medical imaging application used for viewing DICOM files. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates a local attack vector with low attack complexity, no privilege requirements, but requiring user interaction. Successful exploitation could lead to memory corruption with high impact across confidentiality, integrity, and availability dimensions. The vulnerability affects all versions through 2023.3 (Build 9342).

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade MicroDicom DICOM Viewer to version 2024.1 or later
  • Validate all DICOM files from untrusted sources before opening
  • Implement application whitelisting to prevent execution of unauthorized software
  • Apply principle of least privilege for user accounts running DICOM viewer software
  • Monitor for anomalous application crashes or unexpected memory errors
  • Contact MicroDicom directly for additional assistance if needed

Evidence notes

CISA published advisory ICSMA-24-060-01 on February 29, 2024, identifying this vulnerability in MicroDicom DICOM Viewer. The advisory confirms affected versions through 2023.3 (Build 9342) and availability of fix version 2024.1. CVSS vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H sourced from CISA CSAF data.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-25578 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-25578

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-25578 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-25578

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsma-24-060-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-060-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.