<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ics-Medical - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/ics-medical/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 10 Sep 2026 16:06:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/ics-medical/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Heap Out-of-Bounds Write Vulnerability in Orthanc DICOM Server</title><link>https://feed.craftedsignal.io/briefs/2026-09-orthanc-dicom-dos/</link><pubDate>Thu, 10 Sep 2026 16:06:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-orthanc-dicom-dos/</guid><description>An integer overflow vulnerability (CVE-2026-87020) in Orthanc DICOM Server versions prior to 1.13.0 allows an authenticated remote attacker to cause a denial-of-service via a crafted PNG or JPEG image.</description><content:encoded><![CDATA[<p>Orthanc DICOM Server versions prior to 1.13.0 are susceptible to a heap out-of-bounds write vulnerability, tracked as CVE-2026-87020. The vulnerability stems from an integer overflow in the pitch and buffer-size computation logic when the server decodes PNG or JPEG images. An authenticated remote attacker can exploit this flaw by submitting a specially crafted image file to the DICOM server. Successful exploitation results in memory corruption, leading to a process crash and a denial-of-service (DoS) condition. This vulnerability poses a significant risk to healthcare environments where Orthanc is deployed to manage sensitive medical imaging data, as the crash disrupts the availability of critical imaging services. Organizations are advised to update to version 1.13.0 to remediate this flaw.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability affects the Healthcare and Public Health sector globally. A successful attack results in the termination of the Orthanc service, preventing clinicians and medical systems from accessing or processing DICOM imagery. Given the dependency of modern radiology workflows on PACS and image management servers like Orthanc, this disruption can directly impact patient care and diagnostic throughput.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Orthanc DICOM Server to version 1.13.0 or later immediately to patch CVE-2026-87020.</li>
<li>Minimize network exposure by isolating DICOM servers from the public internet and ensuring access is restricted to authorized internal networks only.</li>
<li>Implement network segmentation to place medical imaging infrastructure behind firewalls, restricting direct communication between the DICOM server and non-essential business segments.</li>
<li>Enforce strict authentication controls for the Orthanc web API to reduce the likelihood of unauthenticated or unauthorized users submitting malicious payloads.</li>
<li>Monitor Orthanc application logs for recurring service restarts or unexpected process crashes that may indicate exploitation attempts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>ics-medical</category><category>dos</category></item></channel></rss>