A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
History

Thu, 03 Apr 2025 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Santesoft
Santesoft sante Pacs Server
CPEs cpe:2.3:a:santesoft:sante_pacs_server:4.1.0:*:*:*:*:*:*:*
Vendors & Products Santesoft
Santesoft sante Pacs Server

Fri, 14 Mar 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 16:45:00 +0000

Type Values Removed Values Added
Description A Path Traversal Information Disclosure vulnerability exists in "Sante PACS Server.exe". An unauthenticated remote attacker can exploit it to download arbitrary files on the disk drive where the application is installed.
Title Santesoft Sante PACS Server Path Traversal Information Disclosure
Weaknesses CWE-22
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: tenable

Published:

Updated: 2025-03-14T13:41:13.356Z

Reserved: 2025-03-12T18:58:12.553Z

Link: CVE-2025-2264

cve-icon Vulnrichment

Updated: 2025-03-14T13:40:56.952Z

cve-icon NVD

Status : Analyzed

Published: 2025-03-13T17:15:38.787

Modified: 2025-04-03T18:19:34.337

Link: CVE-2025-2264

cve-icon Redhat

No data.