PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-33606 MicroDicom CVE debrief

CVE-2024-33606 is a high-severity vulnerability in MicroDicom DICOM Viewer affecting versions prior to 2024.2. Published on June 11, 2024, this vulnerability allows an attacker to retrieve sensitive medical images, plant new medical images, or overwrite existing medical images on a victim's system. User interaction is required for exploitation. The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH), indicating significant risk to confidentiality, integrity, and availability of medical imaging data. CISA issued advisory ICSMA-24-163-01 to coordinate disclosure. The vendor has released version 2024.2 to address this issue. Organizations using affected versions should prioritize upgrading to the patched release, as medical imaging systems often contain protected health information (PHI) subject to regulatory requirements.

Vendor
MicroDicom
Product
DICOM Viewer
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-06-11
Original CVE updated
2024-06-11
Advisory published
2024-06-11
Advisory updated
2024-06-11

Who should care

Healthcare organizations, medical imaging departments, radiology practices, and any clinical environments using MicroDicom DICOM Viewer for diagnostic imaging review. Particularly relevant for HIPAA-covered entities and those with regulatory obligations for medical data integrity.

Technical summary

The vulnerability in MicroDicom DICOM Viewer versions prior to 2024.2 enables attackers to manipulate medical image files—including retrieval of sensitive images, injection of falsified images, or overwriting of legitimate images—when user interaction occurs. The network-attackable vulnerability with low attack complexity and required user interaction poses high impact across confidentiality, integrity, and availability dimensions. Medical imaging integrity is critical for diagnostic accuracy and patient safety.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade MicroDicom DICOM Viewer to version 2024.2 or later
  • Review systems for unauthorized medical image modifications if prior versions were in use
  • Implement network segmentation for medical imaging workstations
  • Train users to recognize and avoid suspicious files or links that could trigger exploitation
  • Verify backup integrity for medical imaging data
  • Apply principle of least privilege to DICOM file system access

Evidence notes

Vulnerability confirmed through CISA CSAF advisory with vendor remediation guidance. CVSS 3.1 vector: AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H.

Official resources

Coordinated disclosure via CISA ICS Medical Advisory (ICSMA-24-163-01)