[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fnlfSHGdJ-8mk01XaM1JmvtMhnNosPjpQx15RnIxZ61s":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":24,"created_at":25,"published_at":26,"article":27,"tags":31,"podcasts":50},"b0490604-8532-4366-9201-9edb19e715f3","critical-path-traversal-flaw-in-pydicom-pynetdicom-allows-unauthenticated-file-writes","63de05ba-d2d6-4f32-832c-3dd26353c261","Critical Path Traversal Flaw in pydicom pynetdicom Allows Unauthenticated File Writes","A critical path traversal vulnerability (CVSS 9.1) in the pydicom pynetdicom library allows unauthenticated attackers to write files to arbitrary locations on affected systems running versions 1.0.0 through 3.0.4. Path traversal flaws arise when applications fail to properly sanitize user-supplied input before using it in file system operations, enabling attackers to escape intended directories. This is especially dangerous in a medical imaging context where pynetdicom is commonly deployed, as arbitrary file writes can lead to code execution, data corruption, or compromise of sensitive patient data. The maintainer's lack of response to CISA heightens concern, as organizations relying on this open-source library may not receive timely guidance. This incident underscores the risk of unvetted third-party library dependencies in critical healthcare and research infrastructure.","**Immediate Actions:**\n- Upgrade pynetdicom to version 3.0.4 or later as soon as possible to remediate the vulnerability.\n- Audit all applications and services that depend on pynetdicom and assess their exposure to unauthenticated network access.\n- Restrict network access to any services using the affected library using firewall rules or network segmentation until patching is complete.\n\n**Long-term Improvements:**\n- Maintain a software bill of materials (SBOM) for all projects to rapidly identify which systems are affected when new library vulnerabilities are disclosed.\n- Implement automated dependency scanning (e.g., Dependabot, Snyk, or OWASP Dependency-Check) in your CI\u002FCD pipeline to catch vulnerable libraries before deployment.\n- Establish a vendor\u002Fmaintainer responsiveness policy so that unresponsive open-source dependencies trigger an accelerated internal risk review.\n\n**Detection Measures:**\n- Deploy file integrity monitoring (FIM) on systems running pynetdicom to detect unauthorized or unexpected file writes.\n- Enable logging of all DICOM network service interactions and alert on anomalous file system activity originating from those services.\n- Subscribe to CISA Known Exploited Vulnerabilities (KEV) and NVD feeds to ensure timely awareness of newly disclosed vulnerabilities in your dependency stack.",[12,13,14,15,16,17,18,19,20,21,22,23],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 13 – Network Monitoring and Defense","NIST SP 800-53 SI-2 (Flaw Remediation)","NIST SP 800-53 SI-10 (Information Input Validation)","NIST SP 800-53 CM-3 (Configuration Change Control)","NIST SP 800-218 SSDF PW.5 – Validate All Inputs","NIST Cybersecurity Framework ID.SC-4 (Supply Chain Risk Management)","OWASP Top 10 A01:2021 – Path Traversal \u002F Broken Access Control","HIPAA Security Rule 45 CFR § 164.312(a)(1) – Access Control","HIPAA Security Rule 45 CFR § 164.312(b) – Audit Controls","ITIL Change Management – Emergency Change Procedures","published","2026-06-25T18:21:13.437683+00:00","2026-06-25T18:21:13.349+00:00",{"id":7,"url":28,"slug":29,"title":30},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-medical-advisories\u002Ficsma-26-176-01","pydicom-pynetdicom-library-a97d20","pydicom pynetdicom Library",[32,38,44],{"id":33,"name":34,"slug":35,"description":36,"color":37},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":39,"name":40,"slug":41,"description":42,"color":43},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":45,"name":46,"slug":47,"description":48,"color":49},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]