The default was the vulnerability. Orthanc Server, the widely embedded open-source DICOM server, drew ICSMA-25-037-02 for versions before 1.5.8. CVE-2025-0896, missing authentication for a critical function, base score 9.8.

Expose the remote HTTP interface without explicitly setting AuthenticationEnabled to true, and an unauthenticated attacker could read or modify imaging records or knock the service over. The people who integrate Orthanc into a product inherit that default unless they know to change it, and most integration guides never mention it.

This is separate from the nine-CVE Orthanc note that came a year later. Same server, two advisories, one lesson: ship secure by default, because the default is what most deployments run forever.