CVE-2025-1001 – Medixant RadiAnt DICOM Viewer SSL/TLS Certificate Verification Bypass (MITM)

The following table lists the changes that have been made to the
CVE-2025-1001 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Feb. 21, 2025

    Action Type Old Value New Value
    Added Description Medixant RadiAnt DICOM Viewer is vulnerable due to failure of the update mechanism to verify the update server’s certificate which could allow an attacker to alter network traffic and carry out a machine-in-the-middle attack (MITM). An attacker could modify the server’s response and deliver a malicious update to the user.
    Added CVSS V4.0 AV:A/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    Added CVSS V3.1 AV:A/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
    Added CWE CWE-295
    Added Reference https://www.cisa.gov/news-events/ics-medical-advisories/icsma-25-051-01
    Added Reference https://www.radiantviewer.com/files/RadiAnt-2025.1-Setup.exe
Share the Post:

Related Posts