PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44628 OFFIS DICOM CVE debrief

The OFFIS DCMTK Toolkit is affected by a vulnerability that allows an unauthenticated attacker to crash the worklist server with a single crafted query. The vulnerability exists when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This issue is related to the unauthenticated query functionality. Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Furthermore, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented.

Vendor
OFFIS DICOM
Product
DCMTK
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-06-30
Advisory published
2026-06-30
Advisory updated
2026-06-30

Who should care

Organizations utilizing OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts, should prioritize patching to prevent potential crashes of the worklist server. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified. They should also confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. Additionally, they should plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Finally, they should check relevant monitoring, detection, and logs for exposed assets that need extra review and track exceptions, retest remediated assets, and close the item only after evidence is documented. Affected operators, platforms, and security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Furthermore, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The vulnerability management process should be reviewed to ensure that all affected systems are identified and prioritized for patching. Asset inventory should also be reviewed to ensure that all affected systems are accounted for. Security teams should be aware of the vulnerability and take necessary actions to mitigate it. They should also review the vulnerability management process and asset inventory to ensure that all affected systems are identified and prioritized for patching. Additionally, they should consider implementing additional security controls, such as monitoring and detection, to reduce the risk of exploitation. By taking these steps, organizations can reduce the risk of exploitation and minimize the impact of a potential attack. The affected product or component is OFFIS DCMTK Toolkit. The vulnerability class is related to unaut

Technical summary

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record. This can be done by reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. The vulnerability affects OFFIS DCMTK Toolkit, especially those in industrial control systems and medical advisory contexts.

Defensive priority

Organizations using OFFIS DCMTK Toolkit should prioritize patching to prevent potential crashes of the worklist server.

Recommended defensive actions

  • Apply the latest fix from the GitHub release once it becomes available.
  • Download and implement the latest GitHub release.
  • Verify the Called AE Title / storage directory and lockfile configurations.
  • Monitor worklist server logs for potential crafted queries.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The source item from CISA CSAF provides details on the vulnerability, including the description and affected products. However, further information is limited, and additional verification is recommended. Organizations should verify the Called AE Title / storage directory and lockfile configurations. They should also monitor worklist server logs for potential crafted queries and review compensating controls for exposed systems while remediation is scheduled and verified.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T06:00:00.000Z and has not been modified since then.