Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
History

Thu, 13 Feb 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 13 Feb 2025 01:30:00 +0000

Type Values Removed Values Added
Description Orthanc server prior to version 1.5.8 does not enable basic authentication by default when remote access is enabled. This could result in unauthorized access by an attacker.
Title Orthanc Server Missing Authentication for Critical Function
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2025-02-13T16:44:26.847Z

Reserved: 2025-01-30T18:57:51.377Z

Link: CVE-2025-0896

cve-icon Vulnrichment

Updated: 2025-02-13T16:44:23.105Z

cve-icon NVD

Status : Received

Published: 2025-02-13T02:15:29.470

Modified: 2025-02-13T02:15:29.470

Link: CVE-2025-0896

cve-icon Redhat

No data.