Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE).
References
Configurations
History
26 Nov 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 |
21 Nov 2024, 08:05
Type | Values Removed | Values Added |
---|---|---|
References | () https://discourse.orthanc-server.org/t/security-advisory-for-orthanc-deployments-running-versions-before-1-12-0/3568 - Issue Tracking, Vendor Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2023/09/msg00009.html - | |
References | () https://www.debian.org/security/2023/dsa-5473 - |
12 Sep 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
09 Aug 2023, 20:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
06 Jul 2023, 18:24
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:orthanc-server:orthanc:*:*:*:*:*:*:*:* | |
CWE | NVD-CWE-noinfo | |
References | (MISC) https://discourse.orthanc-server.org/t/security-advisory-for-orthanc-deployments-running-versions-before-1-12-0/3568 - Issue Tracking, Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Orthanc-server orthanc
Orthanc-server |
29 Jun 2023, 15:35
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-06-29 15:15
Updated : 2024-11-26 19:15
NVD link : CVE-2023-33466
Mitre link : CVE-2023-33466
CVE.ORG link : CVE-2023-33466
JSON object : View
Products Affected
orthanc-server
- orthanc
CWE