Cisco Talos shows how DICOM files can be used against imaging systems
Cisco Talos has published a white paper walking through how a heap overflow vulnerability can arise when processing the DICOM file format. The format is both critical and complex, and hospitals build picture archiving and communication systems on it. Such systems often ingest and process files automatically over the network, meaning malformed data can reach vulnerable decoders directly. The study demonstrates concretely how an Orthanc server can be targeted during image upload, resulting in an out-of-bounds write.
What this means for your organisation
The point extends beyond healthcare. Systems that automatically receive and parse files from the network present an attack surface that requires no one to click anything, and they also exist in industry, logistics and case handling. For healthcare organisations, often covered by critical infrastructure requirements, it is a reminder that medical devices and their software must be part of vulnerability management on the same terms as the rest of IT.
Berigo recommends
- Map which systems automatically receive and process files from the network.
- Segment imaging systems and medical devices from ordinary office and client networks.
- Include medical devices and specialist software in vulnerability management and patch plans.
- Require security updates and notification in agreements with clinical system suppliers.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch