CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-1453

Medium Severity
Santesoft
SVRS
30/100

CVSSv3
7.8/10

EPSS
0.00046/1

CVE-2024-1453 in Sante DICOM Viewer Pro allows for information disclosure or arbitrary code execution. A malicious DICOM file, when opened by a user, triggers the vulnerability. While the CVSS score is 7.8, indicating high severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30, suggesting the immediate threat level is relatively low despite being tagged as "In The Wild". This discrepancy indicates that while the vulnerability exists, its exploitation may not be widespread or easily achievable, despite being observed in real-world scenarios. The vulnerability stems from a potential out-of-bounds read (CWE-125). Organizations using affected versions of Sante DICOM Viewer Pro should prioritize patching to mitigate potential risks and maintain data security. Ignoring this issue could lead to sensitive data leaks or system compromise.

In The Wild
CVSS:3.1
AV:L
AC:L
PR:N
UI:R
S:U
C:H
I:H
A:H
2024-03-01

2025-01-16

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

CVE-2024-1453 | Santesoft Sante DICOM Viewer Pro up to 14.0.3 DICOM File Parser out-of-bounds (icsma-24-058-01)
vuldb.com2025-01-17
CVE-2024-1453 | Santesoft Sante DICOM Viewer Pro up to 14.0.3 DICOM File Parser out-of-bounds (icsma-24-058-01) | A vulnerability, which was classified as critical, was found in Santesoft Sante DICOM Viewer Pro up to 14.0.3. This affects an unknown part of the component DICOM File Parser. The manipulation leads to out-of-bounds read. This vulnerability is uniquely identified as CVE-2024-1453
vuldb.com
rss
forum
news

Social Media

No tweets found for this CVE

Affected Software

Configuration 1
TypeVendorProduct
AppSantesoftdicom_viewer_pro

References

ReferenceLink
[email protected]https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-058-01
AF854A3A-2127-422B-91AE-364DA2661108https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-058-01
[email protected]https://www.cisa.gov/news-events/ics-medical-advisories/icsma-24-058-01

CWE Details

CWE IDCWE NameDescription
CWE-125Out-of-bounds ReadThe software reads data past the end, or before the beginning, of the intended buffer.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence