CVE-2023-3892 - CVE House
Back to Database
Status published Medium CVE-2023-3892

Unsafe XML parsing of 3rd party DICOM private tags may lead to XXE

Vulnerability Description

Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd party private RTst metadata tags, transfer the now compromised DICOM object to MIM, and force MIM to archive and load the data. Users on either version are strongly encouraged to update to an unaffected version (7.2.11+, 7.3.4+). This issue was found and analyzed by MIM Software's internal security team.  We are unaware of any proof of concept or actual exploit available in the wild. For more information, visit https://www.mimsoftware.com/cve-2023-3892 https://www.mimsoftware.com/cve-2023-3892 This issue affects MIM Assistant: 7.2.10, 7.3.3; MIM Client: 7.2.10, 7.3.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-3892

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • MIM Software

Affected Vendor

MIM Software

View all reports →

Affected Software

MIM Assistant, MIM Client
Vulnerable Versions:
7.2.10, 7.3.3

Timeline

Official Publish: September 19th, 2023
Last Modified: September 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:H

Weaknesses (CWE)