MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Sante PACS Server Could Allow for Remote Code Execution - PATCH NOW - TLP: CLEAR
ID: e832b060-c9f9-5cd2-8ac5-9891cbf31e3a
STIX ID: report--e832b060-c9f9-5cd2-8ac5-9891cbf31e3a
Feed Name: CISecurity.org Advisories
**Multiple vulnerabilities in Sante PACS Server** include an unauthenticated stack-based buffer overflow in the OpenSSL decryption path allowing remote code execution (CVE-2025-2263), a path traversal information disclosure enabling arbitrary file download (CVE-2025-2264), plus lower-severity issues affecting password storage and a DoS in web login handling (CVE-2025-2265, CVE-2025-2284). Successful exploitation of the RCE could allow attackers to run code as the system user and compromise data or install software.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
