PT-2025-5866 · Unknown · Orthanc Dicom Server

Amitay Dan

+1

·

Published

2025-02-06

·

Updated

2025-07-30

·

CVE-2025-0896

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Orthanc DICOM Server versions prior to 1.5.8
Description The issue allows unauthorized access to medical images due to missing authentication. This exposes medical data to potential unauthorized access. Remote attackers can exploit this to access medical data without authentication.
Recommendations For Orthanc DICOM Server versions prior to 1.5.8, update to version 1.5.8 or enable HTTP authentication to secure your systems.

Fix

Missing Authentication

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-00106
CVE-2025-0896

Affected Products

Orthanc Dicom Server