CVE-2025-52582 is an out-of-bounds read vulnerability in the Overlay::GrabOverlayFromPixelData function of Grassroot DICOM 3.024, which can be triggered by a specially crafted DICOM file, leading to an information leak. This vulnerability is rated 7.5 HIGH on the CVSS scale, indicating a high potential for impact with no user interaction required and low attack complexity. While the FAUCET Risk Score is 85/100, there is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0.24CPE matchmatch criteria | cpe:2.3:a:malaterre:grassroots_dicom:3.0.24:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.