---
cve: "CVE-2022-2119"
severity: "HIGH"
cvss: 7.5
epss: "3.2%"
vendor: "OFFIS"
kev: false
exploited: false
published: "2022-06-24 15:15:10"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-09T22:50:25+02:00"
---

# CVE-2022-2119

> 7.5 HIGH

## Beschreibung

OFFIS DCMTK's (All versions prior to 3.6.7) service class provider (SCP) is vulnerable to path traversal, allowing an attacker to write DICOM files into arbitrary directories under controlled names. This could allow remote code execution.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Benachbart | warn |
| AC Komplexität | Hoch | good |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Patch verfügbar (OSV)

- a137f1aff4e1df3fbefe53ee8b160973c74c96dd (Commit)

## Referenzen

- <https://www.cisa.gov/uscert/ics/advisories/icsma-22-174-01>
- <https://lists.debian.org/debian-lts-announce/2025/06/msg00025.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2022-2119/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
