Medixant RadiAnt DICOM Viewer Improper Certificate Validation Vulnerability Allowing Machine-in-the-Middle Attacks
Vulnerability
A vulnerability exists in Medixant RadiAnt DICOM Viewer version 2024.02 due to the update mechanism's failure to verify the update server's certificate. This flaw could enable an attacker to intercept and alter network traffic, executing a machine-in-the-middle (MITM) attack. Consequently, the attacker could modify the server's response to deliver a malicious update to the user.
Impact
Exploitation of this vulnerability could result in a machine-in-the-middle attack, allowing an attacker to deliver malicious updates to the user.
Remediation
Users are advised to update to version 2025.1 or later. If unable to update, Medixant recommends disabling update notifications and downloading the latest version directly from the RadiAnt website. After downloading, the installation package should be checked with antivirus software before installation.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
