Orthanc Flaws Risk Medical Image Exposure and Remote Code Execution
Orthanc's lightweight, standalone design means a single vulnerable instance can expose sensitive medical images or allow remote code execution, not just cause server crashes. The standard approach of patching the service misses that Orthanc often handles protected health information and supports critical imaging workflows, so compromise impacts patient data confidentiality and availability.
Nine vulnerabilities in Orthanc, including denial of service, information disclosure, and arbitrary code execution, are fixed in version 1.12.11. These flaws stem from insufficient input validation and unsafe memory operations, affecting metadata parsing, decompression, and HTTP request handling. Orthanc's minimal dependencies and standalone nature mean it may be deployed in smaller healthcare or research environments lacking robust monitoring or segmentation.
The presence of remote code execution alongside data leakage risks elevates the urgency for patching exposed Orthanc servers, especially those reachable from the internet. This advisory signals that Orthanc is a recurring target with a broad blast radius, threatening both patient privacy and imaging service continuity beyond a typical server vulnerability.