CVE-2025-1001 Vulnerability in Medixant RadiAnt DICOM Viewer Enables Threat Actors to Perform Machine-in-the-Middle AttacksĀ
ę°ććäøę„ććµć¤ćć¼é²č”č ć«ćØć£ć¦ć®ę°ććŖč åØćäŗŗę°ć®ććå»ēØē»åć®PACS DICOMćć„ć¼ć¢ć¼ć§ććMedixant RadiAnt DICOM Viewerć«ę°ććčå¼±ę§ćēŗč¦ćććććć«ć¼ćäøéč ļ¼MitMļ¼ę»ęćå®č”ć§ććććć«ćć¾ćć
GitHubć«ćććØć2024幓ę«ć¾ć§ć«ęÆę„å¹³å115ä»¶ć®CVEćé示ććć2024幓第3ååęć«ćÆčå¼±ę§ćęŖēØćććµć¤ćć¼ę»ęć124ļ¼ å¢å ćć¾ćććēµęćØćć¦ćęŖēØć®ććć¢ćÆćć£ććŖę¤åŗćÆćäøēäøć®ćµć¤ćć¼ć»ćć„ćŖćć£ćć¼ć ć«ćØć£ć¦ęåŖå äŗé ć®ć¾ć¾ć§ćć
čŖē¤¾ć«åƾććę½åØēćŖę»ęććæć¤ć ćŖć¼ć«ē¹å®ććććć«ćÆć SOC Prime Platform ćÆćéå£ćµć¤ćć¼é²å¾”ć®ććć«ćčå¼±ę§ęŖēØę¤åŗćē®ēćØććå¤ę°ć®Sigmać«ć¼ć«ććć„ć¬ć¼ććć¦ćć¾ćć仄äøć® ę¢ē“¢ę¤åŗ ććæć³ććÆćŖććÆćććØćå®å ØćŖč£½åć¹ć¤ć¼ćć«ćć£ć¦ćµćć¼ćććććčŖååćććč åØćć³ćć£ć³ć°ćAIé§åć®ę¤åŗćØć³ćøćć¢ćŖć³ć°ćććć³ć¤ć³ććŖćøć§ć³ć¹äø»å°ć®č åØę¤åŗć®ććć®é¢é£ć³ć³ććć¹ćč±ććŖę¤åŗć¹ćæććÆć«å³åŗ§ć«ęćäøććććØćć§ćć¾ćććCVEććæć°ä»ćć®Sigmać«ć¼ć«ć©ć¤ćć©ćŖć確čŖććććØć§ćé²åććč åØćč¦éćććØćÆćŖććę¤åŗćÆęÆę„čæ½å ććć¦ćć¾ćć
ćć¹ć¦ć®ć«ć¼ć«ćÆćå¤ćć®SIEMćEDRćććć³ćć¼ćæć¬ć¤ćÆć½ćŖć„ć¼ć·ć§ć³ćØäŗęę§ćććć MITRE ATT&CKćć¬ć¼ć ćÆć¼ćÆ ć«ćććć³ć°ćććč åØčŖæę»ćć¹ć ć¼ćŗć«ćć¾ććććć«ćę¤åŗćÆč©³ē“°ćŖć”ćæćć¼ćæć§å¼·åććć¦ććć CTI åē §ćę»ęćæć¤ć ć©ć¤ć³ćććŖć¢ć¼ćøęØå„Øäŗé ćŖć©ćå«ć¾ćć¦ćć¾ćć
CVE-2025-1001åę
ćć£ćć§ć³ćć¼ćÆćMedixant RadiAnt DICOM Viewerć«ę°ććčå¼±ę§ćēŗč¦ćć¾ććć CVE-2025-1001ćØćć¦čå„ććććć®äøēØåŗ¦ć®ę·±å»åŗ¦ć®ę¬ é„ćÆćCVSSć¹ć³ć¢ć5.7ć§ććCVE-2025-1001ćÆććć¼ćøć§ć³2025.1仄åć®ćć¹ć¦ć®č£½åćć¼ćøć§ć³ć«å½±éæćäøććę“ę°ę©č½ćę“ę°ćµć¼ćć¼ć®čؼęęøćę¤čؼć§ććŖćććØććēŗēćć¾ćććć®ę¬ é„ćÆMitMę»ęć§ęŖēØćććåÆč½ę§ććććč åØć®ć¢ćÆćæć¼ćÆćµć¼ćć¼ć®åæēćååćć¦ęä½ććć¦ć¼ć¶ć¼ć«ęŖęć®ććę“ę°ćé äæ”ććććć®åå³ćäøććććØćć§ćć¾ćć
ććć«ć¼ć対豔ć·ć¹ćć ć§ē¹ęØ©ćęę ¼ćććå “åććµć¼ćć¼ć«ćŖććć¾ććę“ę°ć¦ć£ć³ćć¦ć®å 容ćå¤ę“ććććØćåÆč½ć§ćććććÆćć¦ć¼ć¶ć¼ć証ęęøåć®äøäøč“č¦åćē”č¦ććå½ć®ę“ę°ć確čŖććå “åć«ēŗēćć¾ćććć®ēµęćć»ćć„ćŖćć£ć½ććć¦ć§ć¢ćÆćć”ć¤ć«ćå±éŗćØćæćŖćåÆč½ę§ćććć¾ćć
ē¾ęē¹ć§ćÆćCVE-2025-1001ć®ęŖēØć®čؼę ćÆč¦ć¤ćć£ć¦ćć¾ććććć¦ć¼ć¶ć¼ćÆęę°ćć¼ćøć§ć³ć«ę“ę°ććććććć«ę“ę°ć§ććŖćå “åćÆē·©åēćé©ēØććć¹ćć§ćććć³ćć¼ćÆčæ éć« åé”ć解決ć ć¦ć¼ć¶ć¼ć«č£½åćć¼ćøć§ć³v2025.1仄éćøć®ć¢ććć°ć¬ć¼ććäæćć¦ćć¾ććę“ę°ćć¤ć³ć¹ćć¼ć«ć§ććŖćć¦ć¼ć¶ć¼ć«åƾćć¦ćÆćę½åØēćŖęŖēØč©¦č”ćććććÆććććć®åƾēćå®ę½ććć¹ćć§ććå ·ä½ēć«ćÆćē¹å®ć®ć³ćć³ććå®č”ćć¦å©ēØåÆč½ćŖę“ę°ć®č”Øē¤ŗćē”å¹ć«ććććØć«ćć£ć¦ćę“ę°ćé©ēØććŖćććć«ćććŖć¹ćÆć軽ęøććć¹ćć§ćć
ć°ćć¼ćć«ćŖč åØć¤ć³ććŖćøć§ć³ć¹ććÆć©ć¦ćć½ć¼ć·ć³ć°ćć¼ććć©ć¹ććAIć«åŗć„ćéå£ćµć¤ćć¼é²å¾”ćę“»ēØććććØć§ć SOC Prime Platform ēµē¹ćÆę¢ē„ććć³ę°ćć«åŗē¾ććCVEććæć¤ć ćŖć¼ć«čå„ćć¦åƾåæććććØć§ććµć¤ćć¼ć»ćć„ćŖćć£ć®å§æå¢ććŖć¹ćÆęé©åććććØćć§ćć¾ćć Attack Detective, SOC Primeć®ćØć³ćæć¼ćć©ć¤ćŗåƾåæć®SaaSć§ćēµē¹ćÆč åØć®åÆč¦ę§ćåäøććććµć¤ćć¼é²å¾”ć®ē²ē¹ććæć¤ć ćŖć¼ć«åƾåæććę»ęč ćććčæ éć«č”åććććć«ćč åØę¤åŗč½åć大č¦ęØ”ć«å¼·åććććØćć§ćć¾ćć