On this page
In this issue
-
FDA & US regulatory
Letters, guidance, enforcement
-
CISA KEV & CVEs
Vulnerabilities in your SBOM
-
Standards & international
AAMI, ISO, IEC, EU MDCG
-
What to do this week
Concrete actions for security leads
Key Takeaways
- Multiple vulnerabilities in the OFFIS DCMTK toolkit allow for file restriction bypasses and system crashes via memory exhaustion.
- A Server-Side Request Forgery (SSRF) flaw in OHIF Viewers permits attackers to hijack active user sessions.
- The pynetdicom library contains a path traversal vulnerability that could allow unauthenticated remote attackers to overwrite critical system data.
- Manufacturers of Class II and III diagnostic devices using Python-based DICOM stacks face the highest risk of exploitation.
- Security teams must update OHIF Viewers to version 3.12.1 and pynetdicom to version 3.0.4 immediately.
- Documented patching or compensating controls for these libraries will be expected in upcoming regulatory filings.
The medical imaging sector faces a concentrated wave of vulnerabilities within critical DICOM communication libraries and viewers. Security teams must address high-impact flaws in OFFIS DCMTK, OHIF Viewers, and the pynetdicom library to prevent remote exploitation and unauthorized data overwrites.
Risk management for imaging devices takes center stage this week as three separate vulnerabilities affect the underlying protocols used for transmitting and viewing medical images. These flaws range from memory exhaustion and path traversal to session hijacking, impacting everything from Python-based communication stacks to web-based diagnostic workflows.
For regulatory and security leads, these updates represent more than just technical patches. They are direct indicators of the types of software bill of materials (SBOM) components that the FDA will scrutinize during premarket submissions and postmarket surveillance audits.
In this brief
- Why This Matters
- OFFIS DCMTK Toolkit Memory and Restriction Vulnerabilities
- Session Hijacking via OHIF Viewers SSRF
- Path Traversal in pynetdicom Library
- What to do this week
- How Blue Goat Cyber Helps
- FAQ
Why This Matters
These vulnerabilities target the foundational blocks of medical imaging data exchange. If exploited, they can lead to unauthorized access to patient data, system instability, or the corruption of critical diagnostic information, directly impacting patient safety and clinical workflows.
OFFIS DCMTK Toolkit Memory and Restriction Vulnerabilities
The OFFIS DCMTK Toolkit has been identified as having vulnerabilities that allow attackers to bypass file restrictions or cause system crashes through memory exhaustion.
Session Hijacking via OHIF Viewers SSRF
A Server-Side Request Forgery (SSRF) vulnerability has been discovered in OHIF Viewers.
Path Traversal in pynetdicom Library
The pydicom pynetdicom library contains a critical path traversal flaw.
How Blue Goat Cyber Helps
Blue Goat Cyber provides specialized medical device security services to help manufacturers identify and mitigate vulnerabilities in their software supply chain. Our team, led by Christian Espinosa, assists with penetration testing and regulatory alignment to ensure your devices meet current safety standards. Visit our services page to learn how we support SBOM management and vulnerability disclosure.
FAQ
Get the next issue
Subscribe to stay informed on the latest medical device security threats at /news/the-goats-weekly.
