logo

MS-ISAC CYBERSECURITY ADVISORY - Multiple Vulnerabilities in Sante PACS Server Could Allow for Remote Code Execution - PATCH NOW - TLP: CLEAR

ID: e832b060-c9f9-5cd2-8ac5-9891cbf31e3a

STIX ID: report--e832b060-c9f9-5cd2-8ac5-9891cbf31e3a

Feed Name: CISecurity.org Advisories

Threat Score
72/100

Date Published: 2025-03-14

Date Updated: 2026-04-27

...
...

**Multiple vulnerabilities in Sante PACS Server** include an unauthenticated stack-based buffer overflow in the OpenSSL decryption path allowing remote code execution (CVE-2025-2263), a path traversal information disclosure enabling arbitrary file download (CVE-2025-2264), plus lower-severity issues affecting password storage and a DoS in web login handling (CVE-2025-2265, CVE-2025-2284). Successful exploitation of the RCE could allow attackers to run code as the system user and compromise data or install software.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.