Multiple DCM4CHE Vulnerabilities Enable Deletion, Forgery, and DoS in Medical Imaging Archives
What It Is – An independent researcher disclosed four publicly‑reported bugs in the open‑source DCM4CHE toolkit (used to build DICOM/PACS archives). The flaws allow mass deletion of stored scans, unauthenticated injection or reassignment of studies, and denial‑of‑service via infinite‑loop parsers.
Exploitability – No public evidence of exploitation in a production healthcare environment; proof‑of‑concept code and GitHub Security Advisories are available. CVSS scores are pending.
Affected Products – DCM4CHE (all versions referenced in the advisories) and any commercial or custom PACS solutions that embed the toolkit.
Why It Matters for Trust & Control Assurance
- Demonstrates the need for continuous third‑party risk monitoring; an open‑source component can introduce data‑integrity and availability gaps that affect patient safety.
- Provides concrete evidence that control objectives around vendor oversight, secure configuration, and audit logging must be demonstrable to regulators and auditors.
- Highlights the importance of maintaining up‑to‑date evidence of remediation (patches, configuration baselines) to support a defensible audit trail.
Recommended Actions –
- Apply the patches released in the GitHub Security Advisories immediately.
- Inventory all deployments that include DCM4CHE and map them to your third‑party risk register.
- Enforce network‑level segmentation and strict DICOM/HL7 authentication to limit unauthenticated access.
- Enable detailed logging of archive operations and retain logs for forensic review.
- Conduct a rapid control‑mapping exercise to verify that vendor‑risk and data‑integrity controls meet your framework of record.
Source: DataBreachToday