Script dicom-cfind-ls
Script types:
portrule
Categories:
discovery, safe
Download: https://svn.nmap.org/nmap/scripts/dicom-cfind-ls.nse
Script Summary
Lists DICOM objects stored on a PACS server using C-FIND queries at the STUDY, SERIES, and IMAGE levels. Results are displayed hierarchically showing patients, studies, series and (optionally) individual instances.
The script negotiates an A-ASSOCIATE with the Study Root Query/Retrieve Information Model — FIND SOP Class and issues C-FIND-RQ at each level. It can also retrieve (download) individual DICOM instances using C-GET when the --script-args save option is set.
This is a read-only, non-intrusive reconnaissance script suitable for auditing what data is accessible on a DICOM endpoint without proper access controls.
NOTE: Many PACS servers accept C-FIND from any associated SCU with no authentication. If the server returns results, it means patient data is exposed to any host that can reach the DICOM port — a critical finding for security assessments.
INSTALLATION: This script requires the enhanced dicom.lua library. Copy dicom.lua to your Nmap nselib/ directory: cp dicom.lua /usr/share/nmap/nselib/dicom.lua
Script Arguments
- dicom-cfind-ls.patient_name
Filter by PatientName (wildcard * allowed, default: "*")
- dicom-cfind-ls.patient_id
Filter by PatientID (default: all)
- dicom-cfind-ls.level
Deepest query level: PATIENT, STUDY, SERIES, IMAGE (default: "IMAGE")
- dicom-cfind-ls.study_date
Filter by StudyDate (YYYYMMDD or range, default: all)
- dicom-cfind-ls.full
Include extended return-key tags in queries (StudyDate, AccessionNumber, ModalitiesInStudy, etc.). Some PACS servers abort on unsupported tags; when set the script auto-retries with minimal tags on A-ABORT. Default: off (lean query).
- dicom-cfind-ls.timeout
Response timeout in seconds (default: 10)
- dicom-cfind-ls.max_results
Maximum results per level (default: 100)
- dicom-cfind-ls.save
Directory to save DICOM files via C-GET (default: disabled)
- dicom-cfind-ls.info_model
Q/R Information Model: "study" or "patient" (default: "study")
- dicom-cfind-ls.modality
Filter by Modality (CT, MR, etc., default: all)
- dicom-cfind-ls.max_pdu
Max PDU Length in bytes (default: 16384)
- dicom-cfind-ls.called_ae
Target AE Title (default: "ANY-SCP")
- dicom-cfind-ls.calling_ae
Our AE Title (default: "FINDSCU")
- dicom.called_aet, dicom.calling_aet
See the documentation for the dicom library.
Example Usage
nmap -p 4242 --script dicom-cfind-ls <target>
nmap -p 4242 --script dicom-cfind-ls \ --script-args 'dicom-cfind-ls.called_ae=ORTHANC,dicom-cfind-ls.calling_ae=LAUNCHER' <target>
nmap -p 4242 --script dicom-cfind-ls \ --script-args 'dicom-cfind-ls.level=SERIES,dicom-cfind-ls.max_results=50' <target>
(download all matching instances to disk) nmap -p 4242 --script dicom-cfind-ls \ --script-args 'dicom-cfind-ls.save=/tmp/dicom-dump' <target>
Script Output
PORT STATE SERVICE 4242/tcp open dicom | dicom-cfind-ls: | DICOM Q/R Results (Study Root, FIND): | Patients: 3 Studies: 5 Series: 12 Instances: 47 | | [Patient] John Doe (ID: PATIENT001) | [Study] 2025-01-15 - CT Abdomen (1.2.3.4.5.1) | [Series] CT - 128 images (1.2.3.4.5.1.1) | [Series] CT - 64 images (1.2.3.4.5.1.2) | [Study] 2025-03-20 - MR Brain (1.2.3.4.5.2) | [Series] MR - 256 images (1.2.3.4.5.2.1) | [Patient] Jane Smith (ID: PATIENT002) | [Study] 2025-02-10 - CR Chest (1.2.3.4.5.3) | [Series] CR - 2 images (1.2.3.4.5.3.1) | | WARNING: Patient data accessible without authentication |_ Saved 47 instances to /tmp/dicom-dump/
Requires
Author:
License: Same as Nmap -- See https://nmap.org/book/man-legal.html
action
- action (host, port)
-
MAIN ACTION
Parameters
- host
- port
