Kwetsbaarheden worden geladen…
Kwetsbaarheden worden geladen…
CVE-2026-12473
Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.
Dit record: live koppeling — laatst opgehaald: 25 juli 2026 om 01:42.
Leverancier
Open Health Imaging Foundation (OHIF)
Product
OHIF DICOM Web Viewer Framework
Gepubliceerd
25 juli 2026
Laatst gewijzigd
25 juli 2026
Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
Attack vector
NETWORK
Privileges required
NONE
User interaction
NONE
Vertrouwelijkheid
Geen
Integriteit
Geen
Beschikbaarheid
Geen
Beperkte impact op beschikbaarheid; risico ligt vooral bij vertrouwelijkheid of integriteit van procesdata.
Geen sterke energiesector-specifieke signalen herkend; algemene OT/ICS-relevantie.
The maintainer has fixed the reported vulnerability and released version 3.12.2 (2026-05-18). The fix is located at OHIF/Viewers#5985 (master), OHIF/Viewers#5978 (release/3.12).
IACS Radar-duiding
Classificatie is voorlopig; handmatige verificatie door een OT-securityanalist wordt aanbevolen.
Geclassificeerd door IACS Radar-analysepijplijn (geautomatiseerd) op 25 juli 2026.
IACS Radar-duiding
IEC 62443-mapping
Automatische IACS Radar-duiding op basis van de gerapporteerde CWE-zwakteclassificatie; geen officiële certificeringsuitspraak.