CVE-2024-27628

HIGH

DCMTK <3.6.8 - RCE

Title source: llm
STIX 2.1

Description

Buffer Overflow vulnerability in DCMTK v.3.6.8 allows an attacker to execute arbitrary code via the EctEnhancedCT method component.

Scores

CVSS v3 8.1
EPSS 0.0159
EPSS Percentile 81.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-120
Status published
Products (1)
offis/dcmtk 3.6.8
Published Jun 28, 2024
Tracked Since Feb 18, 2026