Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2023-3892 Details

Description

Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd party private RTst metadata tags, transfer the now compromised DICOM object to MIM, and force MIM to archive and load the data. Users on either version are strongly encouraged to update to an unaffected version (7.2.11+, 7.3.4+). This issue was found and analyzed by MIM Software's internal security team.  We are unaware of any proof of concept or actual exploit available in the wild. For more information, visit https://www.mimsoftware.com/cve-2023-3892 https://www.mimsoftware.com/cve-2023-3892 This issue affects MIM Assistant: 7.2.10, 7.3.3; MIM Client: 7.2.10, 7.3.3.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-611Improper Restriction of XML External Entity Reference[email protected]
CWE-611Improper Restriction of XML External Entity Reference[email protected]

Affected Products

ProductVersions
mimsoftware assistant
7.2.10
7.3.3

CPE

  • cpe:2.3:a:mimsoftware:assistant:7.2.10:*:*:*:*:*:*:*
  • cpe:2.3:a:mimsoftware:assistant:7.3.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.
mimsoftware client
7.2.10
7.3.3

CPE

  • cpe:2.3:a:mimsoftware:client:7.2.10:*:*:*:*:*:*:*
  • cpe:2.3:a:mimsoftware:client:7.3.3:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2023-3892
NVD Published Date:
Sep 19, 2023
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2023-3892 Details - Not Deferred