Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-11687

EPSS 6.69% · P91
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-11687

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
An issue was discovered in the DICOM Part 10 File Format in the NEMA DICOM Standard 1995 through 2019b and continuing in current implementations. The 128-byte preamble of a DICOM file that complies with this specification can contain arbitrary executable headers for multiple operating systems, including Portable Executable (PE) files for Windows and Executable and Linkable Format (ELF) files for Linux-based systems. This space is left unspecified so that dual-purpose files can be created. For example, dual-purpose TIFF/DICOM files are used in digital whole slide imaging applications in medicine. This design flaw enables system-wide compromise as malicious DICOM files are routinely shared between medical devices and hospital systems and transported via removable media for patient care coordination. To exploit this vulnerability, someone must execute the maliciously crafted file. These files can be executable even with the .dcm file extension. Anti-malware configurations at healthcare facilities often ignore medical imagery. DICOM files exist on systems that process protected health information, and successful exploitation could result in violations of regulatory compliance requirements such as HIPAA and FDA postmarket obligations.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
NEMA DICOM 输入验证错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NEMA DICOM是一套医疗数位影像传输协议标准。 NEMA DICOM Standard 1995版本至2019b版本中的DICOM Part 10 File Format存在输入验证错误漏洞。该漏洞源于网络系统或产品未对输入的数据进行正确的验证。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-11687

#POC DescriptionSource LinkShenlong Link
1Explotation framework for CVE-2019-11687https://github.com/kosmokato/bad-dicomPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-11687

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-05-02 · 23 CVEs total

CVE-2017-18373Billion Electric 5200W-T 信任管理问题漏洞
CVE-2019-11675groonga-httpd 竞争条件问题漏洞
CVE-2019-11676ZOHO ManageEngine Firewall Analyzer 跨站脚本漏洞
CVE-2019-11677ZOHO ManageEngine Firewall Analyzer 代码问题漏洞
CVE-2019-11678ZOHO ManageEngine Firewall Analyzer SQL注入漏洞
CVE-2019-11682Taps Lab MailCarrier 缓冲区错误漏洞
CVE-2017-18368ZyXEL P660HN-T1A 操作系统命令注入漏洞
CVE-2017-18369Billion Electric 5200W-T 操作系统命令注入漏洞
CVE-2017-18370ZyXEL P660HN-T1A 操作系统命令注入漏洞
CVE-2017-18371ZyXEL P660HN-T1A 信任管理问题漏洞
CVE-2017-18372Billion Electric 5200W-T 操作系统命令注入漏洞
CVE-2019-9826phpBB 输入验证错误漏洞
CVE-2017-18374ZyXEL P660HN-T1A 信任管理问题漏洞
CVE-2019-11683Linux kernel 缓冲区错误漏洞
CVE-2019-9017SolarWinds DameWare Mini Remote Control 缓冲区错误漏洞
CVE-2018-16716NCBI ToolBox 路径遍历漏洞
CVE-2018-16717NCBI ToolBox 缓冲区错误漏洞
CVE-2018-16718NCBI ToolBox 跨站脚本漏洞
CVE-2018-16960Open XDMoD 跨站脚本漏洞
CVE-2018-16961Open XDMoD 路径遍历漏洞

Showing top 20 of 23 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-11687

No comments yet


Leave a comment