Описание
MicroDicom DICOM Viewer version 2024.03
fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.
Ссылки
- Third Party AdvisoryUS Government Resource
Уязвимые конфигурации
EPSS
5.7 Medium
CVSS3
5.3 Medium
CVSS3
Дефекты
Связанные уязвимости
MicroDicom DICOM Viewer version 2024.03 fails to adequately verify the update server's certificate, which could make it possible for attackers in a privileged network position to alter network traffic and carry out a machine-in-the-middle (MITM) attack. This allows the attackers to modify the server's response and deliver a malicious update to the user.
EPSS
5.7 Medium
CVSS3
5.3 Medium
CVSS3