Back to Database
Status published
High
CVE-2022-2120
OFFIS DCMTK Path Traversal
Vulnerability Description
OFFIS DCMTK's (All versions prior to 3.6.7) service class user (SCU) is vulnerable to relative path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-2120
Credits & Attribution
No credits recorded in the NVD database.
More from OFFIS
View All →CVE-2025-14841
OFFIS DCMTK dcmqrscp dcmqrdbi.cc startMoveRequest null pointer dereference
Medium
4.8
CVE-2025-14607
OFFIS DCMTK dcmdata dcbytstr.cc makeDicomByteString memory corruption
Medium
5.3
CVE-2024-52333
An improper array index validation vulnerability exists in the determineMinMax...
High
8.4
CVE-2024-47796
An improper array index validation vulnerability exists in the nowindow...
High
8.4
CVE-2024-28130
An incorrect type conversion vulnerability exists in the DVPSSoftcopyVOI_PList::createFromImage functionality...
High
7.5
Affected Vendor
OFFIS
View all reports →Affected Software
DCMTK
Vulnerable Versions:
unspecified
Timeline
Official Publish:
June 24th, 2022
Last Modified:
November 3rd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H