HomeMalware & ThreatsMedical Imaging Archive Flaws Endanger Patient Scans

Medical Imaging Archive Flaws Endanger Patient Scans

Published on

spot_img
Open-Source DCM4CHE Bugs Could Enable Deletion, Forgery, Denial-of-Service

Medical Imaging Archive Flaws Endanger Patient Scans
An independent security researcher has identified vulnerabilities in DCM4CHE’s open-source medical imaging archive software that could put patient scans at risk. (Image: DCM4CHE)

Recent findings by independent security researcher Abhinav Agarwal have unveiled several vulnerabilities within the DCM4CHE open-source medical imaging archive. These flaws pose significant risks for patient data, potentially enabling malicious actors to delete stored medical scans, inject fraudulent studies into patient records, and reassign imaging studies to alternate patient identities. The identified vulnerabilities cast a spotlight on the need for enhanced security measures surrounding critical healthcare data.

DCM4CHE is a widely utilized open-source toolkit that facilitates Digital Imaging and Communications in Medicine (DICOM) standards for managing medical images and Picture Archiving and Communications System (PACS) platforms. The importance of these systems cannot be understated, as they are integral in storing and managing critical medical imaging data used by clinicians for patient diagnosis and treatment.

The vulnerabilities discovered by Agarwal include a particularly alarming mass deletion flaw published on GitHub. This vulnerability allows an attacker unfettered access to delete stored patient medical imaging scans that clinicians rely on for comparison studies. Agarwal underscored the severity of the issue, explaining that the archive falsely lists deleted studies as available, leading to confusion and potential medical errors. In such cases, clinicians attempting to retrieve these images would receive errors, severely disrupting their workflow and patient care.

In addition to the mass deletion vulnerability, other advisories released on GitHub highlight problems related to denial-of-service (DoS) risks stemming from infinite loops within the software’s JPEG and MP4 parsers. An attacker exploiting these vulnerabilities could overwhelm the PACS/archive’s processing capacity, rendering the service inaccessible to legitimate users. Agarwal warned that such disruptions could effectively result in a temporary outage of critical healthcare services, negatively impacting patient care.

Moreover, two additional vulnerability findings involving unauthenticated DICOM and HL7 access remain in draft status with DCM4CHE. These could allow attackers to inject forged studies into a specific patient’s record, reassign imaging studies to a different patient’s identity, or even withhold a patient’s record altogether. Agarwal emphasized the risk these vulnerabilities present, indicating that if exploited, they could lead to severe breaches of patient confidentiality and integrity of medical records.

Agarwal has ensured that he is taking appropriate measures by working in coordination with the U.S. Cybersecurity and Infrastructure Security Agency to prepare an advisory concerning the vulnerabilities, including relevant Common Vulnerabilities and Exposures (CVE) identifiers. Thus far, there is no evidence suggesting that any of these vulnerabilities have been actively exploited within healthcare organizations. Agarwal conducted his testing using synthetic patient information deployed in isolated environments, not involving any actual patient records or operational hospital systems.

Despite Agarwal’s initiative to inform the public and relevant authorities of these vulnerabilities, DCM4CHE has yet to respond to inquiries regarding the matter. The implications for users of DCM4CHE are significant, given the integration of this toolkit with several commercial PACS and DICOM software options utilized globally. The researcher specifically mentioned vendors such as MedDream, Mesys, and Comiere, highlighting that it remains unclear whether these independent vendors have been notified or have assessed the vulnerabilities disclosed.

As of now, fixes for these vulnerabilities have not been finalized. In the meantime, Agarwal has recommended several precautionary measures for users. He advises organizations to identify who has access to the DICOM and HL7 interfaces, as well as restrict administrative REST endpoints strictly to authorized personnel. Furthermore, users are encouraged to document and verify the builds of the archives and libraries deployed in their systems, ensuring that they align with the advisories issued. For instance, the Docker images labeled 5.35.2 predate important multipart fixes, posing potential risks if still in operation.

The recognition of these vulnerabilities comes at a critical time, as healthcare institutions increasingly rely on digital solutions for patient management. Documented users of DCM4CHE in the United States include reputable institutions such as Vanderbilt University Medical Center, which has previously discussed the software’s role in its ImageVU research PACS. However, immediate feedback from VUMC regarding the current vulnerabilities remains pending.

Source link

Latest articles

Exvicy ClickFix Malware-as-a-Service Mimics ErrTraffic to Hijack WordPress Sites

Emergence of Exvicy Malware-as-a-Service Platform Targeting WordPress Sites A recently unveiled Malware-as-a-Service platform known as...

F5 Addresses Actively Exploited Zero-Day Vulnerability in BIG-IP APM

F5 Addresses Critical Vulnerability in BIG-IP APM: Immediate Action Required On Tuesday, F5 Networks, a...

CRA Reporting Now Live: Essential Information for Manufacturers, Vendors, and Distributors

EU Cyber Resilience Act: Key Considerations for Manufacturers, Vendors, and Distributors By Matthew Brady, Senior...

More like this

Exvicy ClickFix Malware-as-a-Service Mimics ErrTraffic to Hijack WordPress Sites

Emergence of Exvicy Malware-as-a-Service Platform Targeting WordPress Sites A recently unveiled Malware-as-a-Service platform known as...

F5 Addresses Actively Exploited Zero-Day Vulnerability in BIG-IP APM

F5 Addresses Critical Vulnerability in BIG-IP APM: Immediate Action Required On Tuesday, F5 Networks, a...