Security Advisories
Responsible vulnerability disclosures from our security research.
As part of our security research, we identify and responsibly disclose vulnerabilities in software used in healthcare and critical infrastructure. We work closely with vendors to ensure issues are resolved before publication. Each advisory below documents a confirmed vulnerability along with its impact and recommended mitigation.
ePA-VAU client research
Several advisories below belong to a recurring weakness pattern in lib-vau-based ePA client implementations. We collected them on one page.
View ePA-VAU summarygematik
German Healthcare Infrastructure
1 Critical1 High1 Medium
gematik
German Healthcare Infrastructure
Orthanc
PACS / DICOM Server
3 Critical6 High
Orthanc
PACS / DICOM Server
Orthanc DICOM Server
Heap Buffer Overflow in DICOM Image Decoder (Palette Color Decode)
Orthanc DICOM Server
Heap Buffer Overflow in DICOM Image Decoder via VR UL Dimensions
Orthanc DICOM Server
Out-of-Bounds Read in DICOM Image Decoder (DecodeLookupTable)
Orthanc DICOM Server
Out-of-Bounds Read in DicomStreamReader Meta-Header Parser
Orthanc DICOM Server
Memory Exhaustion via Unbounded Content-Length
Orthanc DICOM Server
Memory Exhaustion via Forged ZIP Metadata
Orthanc DICOM Server
GZIP Decompression Bomb via Content-Encoding Header
Orthanc DICOM Server
Out-of-Bounds Read in DICOM Image Decoder (PMSCT_RLE1 Decompression)
Orthanc DICOM Server
Heap Buffer Overflow in PAM Image Buffer Allocation
OHIF
Web-Based DICOM Viewer
1 High
OHIF
Web-Based DICOM Viewer
OpenMRS
Electronic Medical Record Platform
1 Critical
OpenMRS
Electronic Medical Record Platform
Oviva
ePA Client (Elektronische Patientenakte)
3 High1 Medium
Oviva
ePA Client (Elektronische Patientenakte)
Oviva epa4all-client
VAU Signature Verification Bypass
Oviva epa4all-client
TLS Certificate Validation Disabled in Production
Oviva epa4all-client
IDP Discovery Document Signature Bypass
Oviva epa4all-rest-service
Unauthenticated REST API for Patient Record Writes
med-united
ePA-Middleware (Primärsystem)
1 Critical1 High
med-united
ePA-Middleware (Primärsystem)
DCMTK
OFFIS DICOM Toolkit
1 Critical
DCMTK
OFFIS DICOM Toolkit
Robert Koch Institut (RKI)
Metadata Exchange Platform
1 High
Robert Koch Institut (RKI)
Metadata Exchange Platform
