CVE-2023-3892
Severity CVSS v4.0:
Pending analysis
Type:
CWE-611
Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
19/09/2023
Last modified:
22/09/2023
Description
Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup.<br />
<br />
<br />
<br />
<br />
In order to take advantage of this vulnerability, an attacker must <br />
craft a malicious XML document, embed this document into specific 3rd <br />
party private RTst metadata tags, transfer the now compromised <br />
DICOM object to MIM, and force MIM to archive and load the data.<br />
<br />
Users on either version are strongly encouraged to update to an unaffected version (7.2.11+, 7.3.4+).<br />
<br />
This issue was found and analyzed by MIM Software&#39;s internal security team. We are unaware of any proof of concept or actual exploit available in the wild.<br />
<br />
<br />
For more information, visit https://www.mimsoftware.com/cve-2023-3892 https://www.mimsoftware.com/cve-2023-3892 <br />
<br />
<br />
<br />
<br />
This issue affects MIM Assistant: 7.2.10, 7.3.3; MIM Client: 7.2.10, 7.3.3.<br />
<br />
<br />
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:mimsoftware:assistant:7.2.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:mimsoftware:assistant:7.3.3:*:*:*:*:*:*:* | ||
cpe:2.3:a:mimsoftware:client:7.2.10:*:*:*:*:*:*:* | ||
cpe:2.3:a:mimsoftware:client:7.3.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page