Claroty Team82 uncovers critical vulnerabilities in PACS medical imaging servers that could allow unauthorized manipulation of patient scans.
This video presents a Proof-of-Concept (PoC) exploit targeting CVE-2023-40150, discovered by Claroty's Team82 research team.
The demonstration illustrates how DICOM imaging within a Picture Archiving and Communication System (PACS) server could potentially be replaced or altered, highlighting a specific high-severity vulnerability in healthcare IoT and medical imaging infrastructure.
Key research highlights include:
Technical breakdown of vulnerability CVE-2023-40150 in PACS servers
Demonstration of unauthorized DICOM medical image replacement
Implications for clinical diagnosis integrity and patient safety
Remediation guidance and protective controls for healthcare IoT