Permissions, Privileges, and Access Controls in Orthanc - CVE-2023-33466
Published: August 28, 2023
Vulnerability identifier: #VU80051
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-33466
CWE-ID: CWE-264
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to improperly imposed security restrictions. A remote user with access to the Orthanc API can overwrite arbitrary files on the filesystem.
Affected software
Orthanc
Debian Linux
orthanc (Debian package)
Debian Linux
orthanc (Debian package)
How to mitigate CVE-2023-33466
Install updates from vendor's website.
Orthanc - update to 1.12.0
orthanc (Debian package) - addressed in versions 1.9.2+really1.9.1+dfsg-1+deb11u1, 1.10.1+dfsg-2+deb12u1
orthanc (Debian package) - addressed in versions 1.9.2+really1.9.1+dfsg-1+deb11u1, 1.10.1+dfsg-2+deb12u1